Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

FIM Folders Best Practices?

$
0
0

Hi I am trying to setup FIM to monitor our network for PCI. I have started with the PCI starter monitor but that shows all files on the C:\ that are .dll, .exe or .bat. I have many legit file types like these that are created on multiple directories. Does anyone have any best practices when it comes to which folders are the most vulnerable to attack or that should be watched? Also is it possible to exclude certain subfolders when selecting a monitoring location?

 

Thanks in advance for any help!


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>