Platform capability

Operational

File integrity monitoring and configuration assurance

Detects unauthorised change to critical files, configuration and binaries - one of the highest-signal, lowest-noise detections available.

Overview

File integrity monitoring answers a question that is difficult to evade: has something on this system changed that nobody authorised. Attackers modify configuration to establish persistence, replace binaries to maintain access, and alter logging configuration to reduce their own visibility. All three are changes to files.

Vanguard monitors operating system paths, application configuration, web roots and credential stores. Changes are reported with the account and process responsible, so a legitimate deployment is distinguishable from an unauthorised modification without a manual investigation each time.

It is also one of the few detections that stays quiet in a healthy environment. Silence here is a designed state, not a failure - which is precisely why it is valuable when it does speak.

What this identifies

  • Modification of system binaries and shared libraries
  • Unauthorised change to security and logging configuration
  • Web shells and unexpected files written to web-accessible directories
  • Tampering with scheduled tasks, services and startup configuration
  • Changes to credential and key material stores

Delivery status: Operational - deployed and in production service.

Capabilities

What file integrity & configuration does

  • Real-time change detection

    Monitored paths report additions, modifications and deletions as they happen.

  • Attribution

    Changes are reported with the responsible user and process where the platform can establish them.

  • Configuration drift tracking

    Divergence from an approved configuration baseline, tracked over time.

  • Change-window awareness

    Planned maintenance windows are recognised, so expected change does not generate noise that trains people to ignore the alert.

Under the hood

The engineering underneath

How this capability is actually engineered and operated. The specific detection tooling behind the security operations centre is shared with customers under agreement rather than published, for the same reason you would not publish yours.

  • Integrity monitoring is configured across operating system paths, application configuration, web roots and credential stores.
  • Baselines are established at onboarding and versioned from then on.
  • A quiet integrity channel is treated as a healthy state by the monitoring layer, never as a fault.

The full platform architecture is documented on the architecture page.

Services

Services delivered on this capability

The platform provides the capability. These are the engagements in which Tech49Originals operates it on your behalf.

  • Operational

    Security Monitoring

    An entry-level monitored service for smaller Namibian organisations: continuous detection, alerting and monthly reporting, without a full SOC engagement.

    Explore
  • Operational

    Compliance Monitoring

    Continuous evidence that your security controls are operating, produced automatically rather than reconstructed in the weeks before an audit.

    Explore

Related

  • Operational

    Endpoint Detection & Response

    Agent-based visibility into process execution, persistence, configuration drift and vulnerability state on every monitored host.

    Explore
  • Operational

    SIEM & XDR

    Collects security telemetry from servers, endpoints, network devices and cloud workloads into one correlated detection engine.

    Explore
  • Operational

    Vulnerability Management

    Continuous assessment of operating system packages and application dependencies, prioritised by exploitability and exposure rather than raw severity score.

    Explore

Get started

Find out what is actually happening on your network

A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.