elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
41 stars 450 forks source link

[Meta]File Integrity Monitoring | User Information #3310

Open jamiehynds opened 2 years ago

jamiehynds commented 2 years ago

Similar to Auditbeat's FIM module, our new FIM integration can monitor for file changes, but does not include the user information to capture who modified/accessed the file. This is a significant visibility gap for security analysts and a heavily requested enhancement request.

Research needs to be done to determine how we can capture user information within our FIM integration and any underlying changes required. Can the OS components we rely on today be leveraged or is an underlying change to how we gather FIM data needed?

Linux - https://github.com/elastic/integrations/issues/7401 Windows - #8312 MacOS -

elasticmachine commented 2 years ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

narph commented 1 year ago

split between 3 OS's