FileAudit

FileAudit records and searches file activity across Windows servers and supported cloud storage.

For estates that need searchable file activity records across Windows servers and supported cloud storage.

Record and investigate file activity across storage

File activity is often difficult to review when access, deletion, movement and permission changes are spread across file servers and cloud storage. Finding the relevant event requires enough context to identify the account, device and time involved.

FileAudit centralises file and folder activity into a searchable record. It monitors access events in real time, supports alerts for notable activity, and produces reports on NTFS permissions, changes and file properties. This gives IT teams a clearer record for review and investigation.

Where FileAudit is used

FileAudit is used to review access and changes to files and folders, investigate denied access or deletion events, and identify bulk copy, move or delete activity. It also supports monitoring for mass file encryption and ransomware-generated file extensions, with predefined PowerShell scripts available as alert responses.

The product provides a shared view of activity across Windows file servers and supported cloud storage services, alongside reporting on NTFS permissions and permission changes.

Fits within these solutions

Data Governance & Auditing
File Activity Monitoring
Unstructured Data Visibility
Compliance Reporting
Digital Forensics
Log Management & Analysis

Suitable environments

FileAudit is applicable to Windows file servers, OneDrive for Business, SharePoint Online, Microsoft Teams, Google Drive, Dropbox Business and Box. Its scope is file activity auditing, alerting, reporting and NTFS permission reporting across those supported storage environments.

Benefits

Searchable Activity Record

Provides a central record of file activity for review and investigation.

Event Accountability

Links access events to user, IP address and machine details.

Notable Activity Notification

Brings denied access, deletion and mass file activity to attention through alerts.

Permission Change Visibility

Makes NTFS permissions and permission changes available in reports.

Capabilities

Real-Time File Monitoring

Monitors file and folder access events in real time.

Activity Event Context

Records the user account, IP address and machine name associated with file access events.

Centralised Activity Search

Searches and filters file activity across Windows file servers and supported cloud storage.

File Activity Alerts

Alerts on denied access, deletions and mass copy, delete or move events.

Encryption Detection

Detects mass file encryption and ransomware-generated file extensions.

NTFS Permission Reporting

Reports NTFS permissions, permission changes, and file and folder properties.

Common Use Cases

File Access Investigation

Search file activity to establish who accessed or changed files and folders.

Mass File Activity Review

Alert on bulk copying, deletion or movement of files for timely review.

Ransomware Activity Detection

Detect mass encryption and ransomware-generated file extensions through alerts.

NTFS Permission Review

Report on NTFS permissions, changes and file or folder properties.

Cloud Storage Auditing

Audit file and folder access in supported cloud storage services.

Resources

Screenshots

How would you like to proceed?