File activity is often difficult to review when access, deletion, movement and permission changes are spread across file servers and cloud storage. Finding the relevant event requires enough context to identify the account, device and time involved.
FileAudit centralises file and folder activity into a searchable record. It monitors access events in real time, supports alerts for notable activity, and produces reports on NTFS permissions, changes and file properties. This gives IT teams a clearer record for review and investigation.
FileAudit is used to review access and changes to files and folders, investigate denied access or deletion events, and identify bulk copy, move or delete activity. It also supports monitoring for mass file encryption and ransomware-generated file extensions, with predefined PowerShell scripts available as alert responses.
The product provides a shared view of activity across Windows file servers and supported cloud storage services, alongside reporting on NTFS permissions and permission changes.
FileAudit is applicable to Windows file servers, OneDrive for Business, SharePoint Online, Microsoft Teams, Google Drive, Dropbox Business and Box. Its scope is file activity auditing, alerting, reporting and NTFS permission reporting across those supported storage environments.
Provides a central record of file activity for review and investigation.
Links access events to user, IP address and machine details.
Brings denied access, deletion and mass file activity to attention through alerts.
Makes NTFS permissions and permission changes available in reports.
Search file activity to establish who accessed or changed files and folders.
Alert on bulk copying, deletion or movement of files for timely review.
Detect mass encryption and ransomware-generated file extensions through alerts.
Report on NTFS permissions, changes and file or folder properties.
Audit file and folder access in supported cloud storage services.