Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Effortlessly extract forensic data from computers with enhanced speed and simplicity. Reveal all hidden information within a computer system. Accelerate your search for pertinent data through advanced file indexing and high-performance searching capabilities. Quickly and automatically retrieve passwords, decrypt files, and recover deleted data from various operating systems, including Windows, Mac, and Linux. Utilize features like hash matching and drive signature analysis to uncover evidence and detect suspicious activities. Analyze all files with ease and create an automatic timeline of user interactions. Experience a comprehensive Case Management Solution that allows you to oversee your entire digital investigation through the innovative reporting features of OSF. Customize your reports, incorporate narratives, and attach reports from other tools directly into the OSF documentation. The Volatility Workbench provides a user-friendly graphical interface for the Volatility tool. OSForensics also offers training courses tailored to a wide array of users and expertise levels. Additionally, write a disk image simultaneously to multiple USB flash drives for increased efficiency. This robust functionality sets a new standard in digital forensic investigations.

Description

Quest Change Auditor is a real-time security auditing and threat monitoring solution for Active Directory and broader hybrid Microsoft environments. It monitors configuration changes, administrator actions, user activity, authentication events, and other security-relevant changes across on-premises and cloud systems. Supported environments include Active Directory, Azure AD, Office 365, Windows Server, Exchange, SQL Server, network-attached storage, SharePoint, and OneDrive for Business. Change Auditor detects indicators of compromise and suspicious activity while monitoring lateral movement and post-breach actions across systems such as file servers, Exchange, and Office 365. Threat prevention capabilities can block attackers from modifying critical groups, Group Policy settings and links, sensitive mailboxes, or extracting the Active Directory database to obtain credentials. The platform also identifies common Kerberos authentication vulnerabilities associated with Golden Ticket and Pass-the-Ticket attacks. Normalized audit records convert system activity into readable who, what, when, where, and workstation information together with before-and-after values. Threat timelines and related-event searches help investigators understand how individual changes connect with other security activity across the Microsoft environment. Change Auditor can integrate detailed activity logs with SIEM platforms such as Microsoft Sentinel, Splunk, ArcSight, and QRadar and can generate reports supporting compliance requirements including GDPR, PCI DSS, HIPAA, SOX, FISMA/NIST, and GLBA.

API Access

Has API No 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

Active Directory No 
IBM QRadar SIEM No 
Microsoft 365 No 
Microsoft Entra ID No 
Microsoft Exchange No 
Microsoft OneDrive No 
Microsoft SharePoint No 
Quest Identity Defense No 
SQL Server No 
Skype No 
Splunk Cloud Platform No 

Integrations

Active Directory Yes 
IBM QRadar SIEM Yes 
Microsoft 365 Yes 
Microsoft Entra ID Yes 
Microsoft Exchange Yes 
Microsoft OneDrive Yes 
Microsoft SharePoint Yes 
Quest Identity Defense Yes 
SQL Server Yes 
Skype Yes 
Splunk Cloud Platform Yes 

Pricing Details

$799 per user per year
Free Trial Yes 
Free Version No 

Pricing Details

No price information available.
Free Trial Yes 
Free Version No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows Yes 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs No 
Webinars No 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

PassMark Software

Founded

1998

Country

Australia

Website

www.osforensics.com

Vendor Details

Company Name

Quest Software

Founded

1987

Country

United States

Website

www.quest.com/change-auditor/

Product Features

eDiscovery

Case Analytics Yes 
Compliance Management No 
Discussion Threads No 
Document Indexing No 
Document Tracking Yes 
Full Text Extraction No 
Keyword Search Yes 
Metadata Extraction No 
Topic Clustering No 

Product Features

Alternatives

E3:Universal Reviews

E3:Universal

Paraben Corporation

Alternatives

LLIMAGER Reviews

LLIMAGER

e-Forensics Inc
Aid4Mail Reviews

Aid4Mail

Fookes Software Ltd
Cygna Auditor Reviews

Cygna Auditor

Cygna Labs
ISEEK Reviews

ISEEK

XtremeForensics