Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
CyFIR offers advanced digital security and forensic analysis tools that deliver exceptional visibility at endpoints, enhanced scalability, and rapid resolution times. Organizations with strong cyber resilience experience minimal to no impact when faced with security breaches. The cyber risk solutions provided by CyFIR enable the identification, examination, and mitigation of current or potential threats at a pace 31 times quicker than conventional EDR systems. In today's landscape, where data breaches are increasingly common and more damaging, the need for robust security is paramount. The attack surface for these threats now stretches far beyond an organization's premises, incorporating countless interconnected devices and endpoints scattered across remote sites, cloud environments, SaaS platforms, and various other locations, necessitating comprehensive security measures.
Description
Quest Change Auditor is a real-time security auditing and threat monitoring solution for Active Directory and broader hybrid Microsoft environments. It monitors configuration changes, administrator actions, user activity, authentication events, and other security-relevant changes across on-premises and cloud systems. Supported environments include Active Directory, Azure AD, Office 365, Windows Server, Exchange, SQL Server, network-attached storage, SharePoint, and OneDrive for Business. Change Auditor detects indicators of compromise and suspicious activity while monitoring lateral movement and post-breach actions across systems such as file servers, Exchange, and Office 365. Threat prevention capabilities can block attackers from modifying critical groups, Group Policy settings and links, sensitive mailboxes, or extracting the Active Directory database to obtain credentials. The platform also identifies common Kerberos authentication vulnerabilities associated with Golden Ticket and Pass-the-Ticket attacks. Normalized audit records convert system activity into readable who, what, when, where, and workstation information together with before-and-after values. Threat timelines and related-event searches help investigators understand how individual changes connect with other security activity across the Microsoft environment. Change Auditor can integrate detailed activity logs with SIEM platforms such as Microsoft Sentinel, Splunk, ArcSight, and QRadar and can generate reports supporting compliance requirements including GDPR, PCI DSS, HIPAA, SOX, FISMA/NIST, and GLBA.
API Access
Has API
No
API Access
Has API
No
Integrations
Active Directory
No
IBM QRadar SIEM
No
Microsoft 365
No
Microsoft Entra ID
No
Microsoft Exchange
No
Microsoft OneDrive
No
Microsoft SharePoint
No
Quest Identity Defense
No
SQL Server
No
Skype
No
Integrations
Active Directory
Yes
IBM QRadar SIEM
Yes
Microsoft 365
Yes
Microsoft Entra ID
Yes
Microsoft Exchange
Yes
Microsoft OneDrive
Yes
Microsoft SharePoint
Yes
Quest Identity Defense
Yes
SQL Server
Yes
Skype
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Pricing Details
No price information available.
Free Trial
Yes
Free Version
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
Yes
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
CyFIR
Founded
2010
Country
United States
Website
www.cyfir.com
Vendor Details
Company Name
Quest Software
Founded
1987
Country
United States
Website
www.quest.com/change-auditor/
Product Features
Endpoint Detection and Response (EDR)
Behavioral Analytics
No
Blacklisting/Whitelisting
No
Continuous Monitoring
No
Malware/Anomaly Detection
Yes
Prioritization
No
Remediation Management
No
Root Cause Analysis
No
Incident Response
Attack Behavior Analytics
No
Automated Remediation
No
Compliance Reporting
No
Forensic Data Retention
No
Incident Alerting
No
Incident Database
No
Incident Logs
No
Incident Reporting
No
Privacy Breach Reporting
No
SIEM Data Ingestion / Correlation
No
SLA Tracking / Management
No
Security Orchestration
No
Threat Intelligence
No
Timeline Analysis
No
Workflow Automation
No
Workflow Management
No