Quest Change Auditor Description
Quest Change Auditor is a real-time security auditing and threat monitoring solution for Active Directory and broader hybrid Microsoft environments. It monitors configuration changes, administrator actions, user activity, authentication events, and other security-relevant changes across on-premises and cloud systems. Supported environments include Active Directory, Azure AD, Office 365, Windows Server, Exchange, SQL Server, network-attached storage, SharePoint, and OneDrive for Business. Change Auditor detects indicators of compromise and suspicious activity while monitoring lateral movement and post-breach actions across systems such as file servers, Exchange, and Office 365. Threat prevention capabilities can block attackers from modifying critical groups, Group Policy settings and links, sensitive mailboxes, or extracting the Active Directory database to obtain credentials. The platform also identifies common Kerberos authentication vulnerabilities associated with Golden Ticket and Pass-the-Ticket attacks. Normalized audit records convert system activity into readable who, what, when, where, and workstation information together with before-and-after values. Threat timelines and related-event searches help investigators understand how individual changes connect with other security activity across the Microsoft environment. Change Auditor can integrate detailed activity logs with SIEM platforms such as Microsoft Sentinel, Splunk, ArcSight, and QRadar and can generate reports supporting compliance requirements including GDPR, PCI DSS, HIPAA, SOX, FISMA/NIST, and GLBA.
Pricing
Integrations
Company Details
Product Details
Quest Change Auditor Features and Options
Quest Change Auditor User Reviews
Write a Review- Previous
- Next