Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Meta]File Integrity Monitoring | User Information #3310

Open
jamiehynds opened this issue May 10, 2022 · 2 comments
Open

[Meta]File Integrity Monitoring | User Information #3310

jamiehynds opened this issue May 10, 2022 · 2 comments
Labels
enhancement New feature or request Integration:fim File Integrity Monitoring Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform]

Comments

@jamiehynds
Copy link

jamiehynds commented May 10, 2022

Similar to Auditbeat's FIM module, our new FIM integration can monitor for file changes, but does not include the user information to capture who modified/accessed the file. This is a significant visibility gap for security analysts and a heavily requested enhancement request.

Research needs to be done to determine how we can capture user information within our FIM integration and any underlying changes required. Can the OS components we rely on today be leveraged or is an underlying change to how we gather FIM data needed?

Linux - #7401
Windows - #8312
MacOS -

@elasticmachine
Copy link

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@narph
Copy link
Contributor

narph commented Jul 19, 2023

split between 3 OS's

@narph narph changed the title File Integrity Monitoring | User Information [Meta]File Integrity Monitoring | User Information Aug 16, 2023
@narph narph added Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform] and removed Team:Security-External Integrations labels Jan 29, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request Integration:fim File Integrity Monitoring Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform]
Projects
None yet
Development

No branches or pull requests

4 participants