Change Guardian monitors the following in Windows:
File integrity
File shares
File systems
Local users and groups
Processes
Registry
Removable media
This section provides the following information:
Complete the following tasks to start monitoring Windows events:
Task |
See |
---|---|
Complete the prerequisites |
|
Add a license key |
|
Configure Change Guardian for monitoring |
|
Triage events |
NOTE:Change Guardian monitors removable media events only on USB flash drives. To monitor external hard disk drive (HDD), create a file system monitoring policy on the mounted drive.
Ensure that you have completed the following:
File integrity: Policies about changes to critical startup file
File shares: Policies about creating file shares and monitoring permission changes
File systems: Policies about monitoring binary files and permission changes to system directories, privileged profiles, and security analysis database
Local users and groups: Policies about the following:
Changes to administrator group membership and administrator group privileges
Creating, deleting user account, and changes to password
Enabling, disabling, modifying administrator, and changing administrator privilege
Processes: Policies about executing undesirable processes
Registry: Policies about changes to application installation, changes to service registration, and so on.
Removable media: Policies about attaching removable media and file writing to the removable media
For Change Guardian to monitor the registry enable the Registry Browser. Set the HKLM\Software\Wow6432Node\NetIQ\ChangeGuardianAgent\repositoryEnabled flag to 1 and restart the agent. If you do not manually set the flag to 1, Registry Browser displays the error message: Could not connect to Windows Data Source.
To create a policy to monitor Local Users and Groups, in Policy Definition, select event list, or Privilegelist, or both.
For information about creating policies, see Creating Policies.
After creating policies, you can assign them to assets. For information about assigning policies, see Working with Policies.