如需獲得最佳網頁瀏覽體驗,請使用 IE 11 或更高版本、Chrome、Firefox 或 Safari。

Change Auditor for Logon Activity

跟踪AD登录和注销活动以及Azure AD登录,并发出相应警报

How to audit user network logon activity in Change Auditor for Logon Activity 05:02

不断增加的合规性法规和安全性顾虑,使得自动化、可靠且全面地跟踪用户登录和注销活动变得不可或缺。 遗憾的是,大多数第三方工具的实施过程非常繁琐,而且无法提供所需的审核级别来确保对用户操作的充分问责制。 原生工具缺乏取得成功所需的可见性、警报、审核和数据安全性。

借助Change Auditor for Logon Activity,您可以通过捕获所有AD登录/注销和Azure AD登录活动并提供相应警报和报告,从而提高企业的安全性与合规性并优化审核。 跟踪Kerberos和NTLM身份验证,以帮助前瞻性地发现漏洞。

托管控制板

On Demand Audit中,通过灵活的搜索和丰富的可视化功能来查看所有AD登录/注销、Azure AD登录以及Office 365活动。

直观显示

跟踪关键登录活动,并提供关于活动的执行人员、内容、时间、地点和工作站的详细信息。

用户活动审核

审核管理员活动的时间表,从登录到注销以及其间的所有操作都包括在内(与其他Change Auditor模块结合使用时)。

SIEM集成

与SIEM解决方案相集成,将Change Auditor事件转发到Splunk、Arcsight或QRadar。

黄金票据检测

检测在黄金票据/票据传递攻击期间使用的常见Kerberos身份验证漏洞,并发出相应警报。

NTLM身份验证审核

检测仍在使用安全性较低的NTLM身份验证的应用程序。

合规性就绪的报告

简化登录活动收集,以符合主要外部法规和内部安全策略。

随时随地获得实时警报

向电子邮件地址和移动设备发送关键更改和模式警报,让您即便不在现场也能收到有关立即采取措施的提醒。

On Demand Audit Hybrid Suite for Office 365

On Demand Audit Hybrid Suite for Office 365

升级到On Demand Audit Hybrid Suite for Office 365,其包含Change Auditor for Logon Activity以及Change Auditor for Active Directory和On Demand Audit。 只需点击几下即可轻松将它们搭配使用,在单个托管视图中查看AD、Azure AD、Exchange Online、SharePoint Online和OneDrive for Business中所做的所有更改。 通过响应快速的搜索和交互式数据可视化简化调查,并可将审核历史记录保留长达10年。

功能

妥善做法报告

获得全面的报告,以便符合妥善做法,如报告访问、成功登录和失败登录;授权对比报告;根据用户分组的报告。

混合安全感知

报告AD用户登录和注销,并与Azure AD登录相关联以帮助发现混合云环境中的可疑活动。 捕获的信息包括登录类型、IP地址和地理位置、获得身份验证的应用程序以及登录尝试是否成功。

相关搜索

只需单击一下,便可立即访问关于您所查看更改的所有信息以及所有相关事件(包括由特定用户进行的所有其他更改),从而消除额外的不确定因素和未知安全隐患。

安全性时间表

支持查看、突出显示和筛选随时间推移顺次发生的登录活动及相关更改事件,以便更好地对这些事件和趋势进行取证分析。

增强安全洞察

将大量系统和设备中的不同IT数据关联到IT Security Search(一种交互搜索引擎)中,以加快安全事件响应和取证分析速度。 通过丰富的可视化和事件时间表囊括用户授权和活动、事件趋势、可疑模式等。

Quest InTrust集成

Quest InTrust相集成,实现20:1的压缩事件存储和集中化的原生或第三方日志收集,进行解析和分析并对可疑事件(例如已知勒索软件攻击或可疑PowerShell命令)发出警报和自动执行响应操作。
荣获2018年Stevie Awards美国人民选择奖

荣获2018年Stevie Awards美国人民选择奖

在2018年Stevie Award美国人民选择奖的角逐中,Change Auditor得票最多,荣获最佳软件奖,此外,还获得2018年最佳新产品银奖。

规格

Change Auditor协调器(服务器端)、Change Auditor客户端、Change Auditor代理程序(服务器端)、Change Auditor工作站和Web客户端(可选组件)具有特定的系统要求。 有关Change Auditor可以审核的所有组件和目标系统的完整系统要求与所需权限列表,请参见Change Auditor安装指南

Change Auditor协调器负责执行客户端和代理程序的请求并生成警报。

处理器

等效于四核英特尔®酷睿™ i7或更高配置的处理器

内存

最低:8 GB内存或更高配置

建议:32 GB RAM或更高配置

SQL Server

最高支持以下版本的SQL数据库:

  • Microsoft SQL Server 2012 SP4
  • Microsoft SQL Server 2014 SP3
  • Microsoft SQL Server 2016 SP2
  • Microsoft SQL Server 2017
  • Microsoft SQL Server 2019
  • 注意:Change Auditor支持SQL AlwaysOn可用性组、SQL群集以及应用了行和页面压缩的数据库

    操作系统

    最高支持以下版本的安装平台(x64):

    • Windows Server 2012
    • Windows Server 2012 R2
  • Windows Server 2016
  • Windows Server 2019
  • :必须启用Microsoft Windows Data Access Components (MDAC)。 (MDAC是操作系统的一部分,默认情况下已启用。)

    协调器软件和配置

    为实现卓越的性能,Quest强烈建议:

    • 专用成员服务器上安装Change Auditor协调器。
    • 应在单独的专用SQL Server实例上配置Change Auditor数据库。

    :请勿为Change Auditor数据库预分配固定大小。

    此外,需要满足以下软件/配置要求:

    • 协调器必须拥有与本地域和林根域中所有域控制器的LDAP和GC连接。
    • Microsoft .NET 4.7.1(x64版)
    • Microsoft XML Parser (MSXML) 6.0(x64版)
    • Microsoft SQLXML 4.0(x64版)
    协调器占用空间
    • 预计使用1 GB的硬盘空间。
    • 协调器占用的内存大小主要取决于环境、代理程序连接数和事件量。
    • 估计的数据库大小因所部署的代理程序数量和所捕获的审核事件数量而异。

    有关其他所需的帐户协调器最低权限,请参见Change Auditor安装指南

    资源

    Change Auditor for Logon Activity
    数据表
    Change Auditor for Logon Activity
    Change Auditor for Logon Activity
    在 AD 登入與登出、以及 Azure AD 登入活動發生時,發出警示並報告
    阅读数据表
    Top 10 Security Events to Monitor in Azure Active Directory and Office 365
    电子书
    Top 10 Security Events to Monitor in Azure Active Directory and Office 365
    Top 10 Security Events to Monitor in Azure Active Directory and Office 365

    Is your organization really more secure now that you’re running applications in the cloud?

    Don’t forget that users can still perform high-risk actions in the cloud, and account c

    阅读电子书
    Manufacturer ensures security and GDPR compliance
    案例分析
    Manufacturer ensures security and GDPR compliance
    Manufacturer ensures security and GDPR compliance

    To continue to thrive in its competitive market, Beltrame Group had modernized its IT environment, with help from Que

    阅读案例分析
    Top 5 Office 365 and Azure AD Security Events to Monitor During the COVID-19 Crisis
    网络点播
    Top 5 Office 365 and Azure AD Security Events to Monitor During the COVID-19 Crisis
    Top 5 Office 365 and Azure AD Security Events to Monitor During the COVID-19 Crisis

    Increase in remote workers means explosive adoption and utilization of Office 365 workloads such as Teams, SharePoint Online, OneDrive for Business and Exchange Online. Malicious actors can tr

    观看网络直播
    Howard County, Maryland, improves security and service availability, while saving hours of IT work, with solutions from Quest.
    案例分析
    Howard County, Maryland, improves security and service availability, while saving hours of IT work, with solutions from Quest.
    Howard County, Maryland, improves security and service availability, while saving hours of IT work, with solutions from Quest.
    Howard County, Maryland, uses Microsoft platform management solutions from Quest, which enable accurate and efficient account provisioning, Group Policy administration, change auditing, disaster recovery, and more — while saving the IT team hours of work.
    阅读案例分析
    How to search and alert on suspicious logon activity in AD and Office 365
    How to search and alert on suspicious logon activity in AD and Office 365

    06:02

    視頻
    How to search and alert on suspicious logon activity in AD and Office 365
    Discover how to search and alert on suspicious logon activity in your AD, Office and hybrid environment with the On Demand Audit Hybrid Suite.
    观看视频
    Overcoming Office 365 Security & Compliance Auditing Challenges
    白皮书
    Overcoming Office 365 Security & Compliance Auditing Challenges
    Overcoming Office 365 Security & Compliance Auditing Challenges

    Commercial use of Office 365 has skyrocketed in recent years — but most organizations admit they still lack the

    阅读白皮书
    Extra Vigilance: Top 3 Ways to Adapt Your Security Log Monitoring for the Surge in Working from Home
    网络点播
    Extra Vigilance: Top 3 Ways to Adapt Your Security Log Monitoring for the Surge in Working from Home
    Extra Vigilance: Top 3 Ways to Adapt Your Security Log Monitoring for the Surge in Working from Home

    With the rapid increase of employees working from home, you will need to throw out your old baseline of normal audit activity – especially on the network plane. Users are working on insecure

    观看网络直播

    博客

    Change Auditor 7.1: What’s New

    Change Auditor 7.1: What’s New

    The Change Auditor for Logon Activity 7.1 update allows for auditing of Kerberos and NTLM authentications to promote better security and compliance. Learn more.

    Quest Security Assessments Reveal Top 4 Issues in Active Directory: Groups and OSs (Part 3 of 3)

    Quest Security Assessments Reveal Top 4 Issues in Active Directory: Groups and OSs (Part 3 of 3)

    In the third and final part of this Active Directory security issues series, we take a look at the problems with Groups and Operating Systems (OSs). Learn more.

    CISA Office 365 Alert and 10 Security Actions to Take Now by Sean Metcalf (from our latest TEC Talk)

    CISA Office 365 Alert and 10 Security Actions to Take Now by Sean Metcalf (from our latest TEC Talk)

    This blog post will outline the CISA alert, prior CISA advice for securing Office 365 and point you to a TEC Talk by Microsoft Certified Master Sean Metcalf (@PyroTek3) that addresses the 10 (and more) Azure AD and Office 365 security tasks to do now!

    Workforce and IT Refresher Tips to Avoid COVID-19 Phishing Attempts

    Workforce and IT Refresher Tips to Avoid COVID-19 Phishing Attempts

    “Let no crisis go to waste.” This is the new mantra of every cyber criminal in the age of COVID-19. Around the globe, organizations are seeing an increase in phishing attempts that exploit our fear and desire for coronavirus information, ...

    The Many Colors of AD Security – Microsoft Red Forest, Orange Forest, Greenfield or Blue?

    The Many Colors of AD Security – Microsoft Red Forest, Orange Forest, Greenfield or Blue?

    Discover the different models of Active Directory (AD) security, including the Red and Orange Forest models, Greenfield migrations, and Blue Team.

    Top 10 Security Events to Monitor in Azure AD and Office 365 – [New eBook]

    Top 10 Security Events to Monitor in Azure AD and Office 365 – [New eBook]

    Learn about 10 places in your cloud environment that log important audit events. See how native tools fall short of ensuring your auditing compliance.

    立即行动

    针对AD登录和注销以及Azure AD登录活动发出相应警报并进行报告。

    支持和服务

    产品支持

    自助式工具将帮助您安装、配置产品以及进行故障排除。

    支持服务

    查找适当的支持级别,以满足企业的独特需求。

    专业服务

    从现场或异地提供的一系列可用服务中进行搜索,以最好地满足您的需求。

    培训与认证

    通过网络在线、现场或虚拟形式提供教师指导的培训课程。