ProTip: How to Utilize the New Investigate Feature in StealthDEFEND 1.1

ProTip: How to Utilize the New Investigate Feature in StealthDEFEND 1.1

The latest release of StealthDEFEND 1.1 brings us a new highly anticipated feature, Investigations. This brings a new custom experience to the threats and alerts you see in the product by allowing you to define your own threats by specifying the: who, what, where, and when.

StealthDEFEND 1.1, StealthDEFEND 1.1 Investigate, Threat Analytics, Investigate Threats

By navigating to the “Investigate” page in the menu, you are presented with the file activity events for the current day along with the top hosts, top users, and event details. I really like utilizing this page to have a quick glance at my file activity for the day. Additionally, this allows me to click on a user or a host to get more details about the events associated with either.

 

The real value here is creating investigations and alerts of your own. Suppose you want to monitor a specific employee during their last couple weeks on the job or maybe you want to monitor a specific sensitive set of shares in your file system and receive alerts when certain file actions occur. This can all be done with the extensive filters while creating a new investigation. Plus, if you already currently leverage STEALTHbits Sensitive Data Add-On for StealthAUDIT, you can bring in sensitive data context to your StealthDEFEND console. The ability to do this makes the product a complete purpose-built machine learning solution around Data Access Governance.

StealthDEFEND 1.1, StealthDEFEND STEALTHbits Sensitive Data Add-On for StealthAUDIT, Data Access Governance, Data Governance

After saving a new investigation if will appear in your saved investigation library. You can also save it as an alert, which allows you to receive e-mail alerts any time that filtered activity is triggered or even send the alert to your SIEM device if you have one. A lot of my current customers love leveraging the SIEM integration to receive the general out of the box threats like High Risk Permission Changes and Abnormal Activity.

StealthDEFEND 1.1, StealthDEFEND 1.1 SIEM Integration, SIEM solution, SIEM Dashboard, SIEM integration, High Risk Activity, User Activity Monitor

The product team is adding in actions in the next release of StealthDEFEND which will allow users to take action on the threats. These actions include automatically locking down a user, moving a user to a different location, reversing high-risk permission changes, and more. Stay tuned for more information about the next release!

Head over to our website to learn more about StealthDEFEND 1.1 and how your organization can stay on top of abnormal file activity behavior.

Dan is a Presales Engineer at STEALTHbits Technologies. Prior to moving over to Presales, Dan worked as a Technical Product Manager.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Start a Free StealthAUDIT® Trial!

No risk. No obligation.