AD Change Happens on DCs
AD Change Happens on DCs
Change Happens. Users come and go, their properties change, policy needs are revised, and groups have their memberships updated. Changes are made all over your organization, and they eventually find their way to your Domain Controllers where objects are modified and the changes replicate throughout your organization. Keeping tabs on all of these changes is a tricky proposition, but it’s our job to make it simple here at STEALTHbits.
We all know that changes actually happen on DCs, and when the change happens the actual source DC is stamped on the object, so that's easy to figure out. The much trickier part is understanding where the change request is coming from. It's only on rare occasions that the application making the request is actually on the DC itself, so the vast majority of the time the changes come from elsewhere - and this is where a good product will give you that leg up on the standard change events that Microsoft provides. Armed with the workstation that the change originated from, the protocol used, and the port bound to for the change, you can answer questions like:
- Which of the services that this service account is running on actually made the change? What machine is it on?
- Where does Bob the Administrator make most of his changes?
- Bob just made 250 changes from CindyWorkStation. Is this an intended set of changes, or is someone getting access to Bob's account to make an out-of-bounds change?
- Are my admins making their changes on machines in the same site, or are they reaching outside of site boundaries to make changes on DCs that aren't best for them? Are my sites misconfigured somewhere?
Clearly, this is valuable information and it's annoying that you can't get it from Microsoft's native event logging for AD Changes. Luckily there’s an alternative, and that alternative is StealthINTERCEPT Directory Authority. Direct, in-line integration within the Active Directory event stream itself allows StealthINTERCEPT to elevate hidden change event details to the surface, such as the machine or application a change originated from, providing that missing piece of information that can be critical to making not just good, but informed decisions in the management of your Active Directory implementation.
Entitlement Reviews on Unstructured Data
Entitlement Reviews on Unstructured Data
Whether you’re already conducting entitlement reviews and are looking to bring unstructured data into the process or are just getting started and have concerns across your file systems and other unstructured data sources, STEALTHbits can help.
Collection
We’ve developed the fastest, most thorough, most flexible content scanners in the industry to collect and organize unstructured content from numerous sources. Our data collection architecture scales to support the world’s largest environments. Scheduling is flexible and scans can be scoped to match specific requirements.
Analysis
Our advanced analysis engine also provides valuable answers that can provide context around your data before it’s brought into your entitlement review process. All data is not created equal. Some content is considered high-risk. Other content may be just wasting valuable resources. STEALTHbits can help you make sense of your unstructured data and answer critical questions about high risk conditions and other topics so that your entitlement reviews can be as efficient as possible.
Workflow and Action
STEALTHbits provides a flexible approach to process workflow. Content owners can be automatically surveyed to determine which content they own and where priority should be placed. The workflow may also consider information that is already known such as which content should be open to everyone or which is considered sensitive. The workflows can take additional action as well such as closing down open file shares or generating security groups based on actual usage activity. The workflows are flexible and the actions are powerful.
Integration
If you already have an entitlement review process in place, STEALTHbits can collect, analyze, act, and then incorporate unstructured data into your existing solution. Solutions designed for advanced entitlement review processes may not be well-suited for data collection or analysis. STEALTHbits’ pluggable architecture makes integration simple and effective.
Let us know if you’d like to hear more.
File Share Entitlement Review: Finding the Owner
File Share Entitlement Review: Finding the Owner
One thing top of mind for information security professionals in 2012 is understanding who has access to what and being able to provide clear, concise reporting around it. We call it Access Governance or Data Governance and it consists of entitlement reviews, access reviews, or audit reporting. The terms overlap and the complete superset of product features around this challenge can seem overwhelming and difficult to comprehend. At STEALTHbits, we simplify things. We’ve developed quick-win solutions that get you from where you are today to the next step with a proven and pragmatic methodology.
Data Owners
One small example is how we’re able to identify owners of file shares and other resources. First, we have an algorithm that provides a list of probable owners based on a number of factors – who has rights, who is doing what, etc. The algorithm is adjustable to meet specific requirements, but we know that there isn’t an algorithm on earth that could determine ownership with 100% accuracy across large scale environments. So, we leverage the STEALTHAudit Platform survey modules to reach out to probable data owners to ask them if we’re right.
If we are, we provide a set of instructions on what we need them to do. If they’re not, we move on to the next probable owner to see if we can track down the right people. Each step of the way, we report on where things stand: which shares are high-risk, which have owners, which are still awaiting response, etc.
In large scale environments, there is no easy button. But there is experience and expertise. Experience counts. If you’re trying to figure out who owns your content, let’s chat and we’ll let you know what we’ve learned about this challenge as we’ve helped a number of the world’s largest organizations solve it.
Open File Shares: A Pragmatic Approach
Open File Shares: A Pragmatic Approach
A number of STEALTHbits’ customers have reported that their #1 audit challenge boils down to open file shares. Auditors are clearly concerned with access and while it’s difficult to understand access rights across millions of individual files, it’s immediately apparent when there are file shares that are open to anyone.
But, how do you approach a problem that spans across thousands of servers? Do you implement a monitoring solution for three months? Manually sift through each one? Well, you could do either of those things. And if you’re interested in activity monitoring, we’ve got the best solution on the market. But, I’d argue that the best way to deal with open shares is to move through a quick, pragmatic process that scopes resources, identifies high-risk, and automates cleanup without significant infrastructure or investment.
STEALTHbits has developed a step-by-step approach to closing down open file shares and has proven it out at a number of the world’s largest organizations. It’s simple to deploy, uses a just single server, can scan remotely, and it works. We’re able to provide real results in about one week. Give us 5 days, and we’ll have your arms comfortably around the problem and your mind at rest.


![Login [img]](/images/stories/btn-login.png)
