1/10
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
FIM (File Integrity Monitor)
Software that detects unauthorized changes to files that should rarely or never change, such as core application executables and OS files.
SFC (System File Checker)
Windows' built-in, on-demand FIM utility; scans critical OS files, detects modifications, and replaces bad files with known-good versions.
Tripwire
Popular Linux FIM utility offering real-time file change monitoring.
Host-based IPS + FIM
Host-based IPS can combine attack blocking with file integrity monitoring, since it runs directly on the OS and can see the whole file system.
FIM vs configuration drift
Configuration drift is a system's settings deviating from baseline over time. FIM catches specific unexpected file modifications. Same underlying philosophy, different granularity.
DLP for data in use
Endpoint DLP monitoring data actively loaded in a system's memory.
DLP for data in motion
Network-connected DLP watching packets in real time as they cross the network; can be integrated into an NGFW or run as a standalone appliance.
DLP for data at rest
DLP monitoring files stored on a server or OS's file system, typically running as local software.
USB/removable media DLP controls
DLP policies specifically governing USB device usage, allowing, blocking, or restricting data transfer via removable storage; a device-level control, not content scanning.
Cloud-based DLP
DLP functioning as a cloud appliance, monitoring traffic in and out of cloud application instances; can also block malware, not just sensitive data.
Email-based DLP
DLP scanning inbound email for spoofing or suspicious keywords and outbound email for sensitive data (SSNs, wire transfer fraud, W-2 info) before it leaves the organization.