Windows file integrity monitoring

Windows file integrity monitoring from the log agent you already run.

Watch critical files, folders and wildcards on a schedule, and send every change to your SIEM through the same pipeline as your Windows event logs. No second agent, no extra licence.

  • Files, folders, wildcards
  • Every 15 min, hourly or daily
  • Re-baselines in the audit log
  • PCI DSS v4.0.1 11.5.2

In short

DPLens adds Windows file integrity monitoring (FIM) to the log agent you already deploy: it scans the files, folders and wildcards you choose every 15 minutes, hourly or daily, compares them with a recorded baseline, and sends changes to your SIEM as events. Scans run far more often than the at-least-weekly comparison in PCI DSS v4.0.1 requirement 11.5.2.

How it works

How does file integrity monitoring work in DPLens?

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. File integrity is one of its five source types, beside Windows Event Log, log files, syslog and NetFlow. Each file-integrity source holds a list of watch items, and each watch item is a path and a schedule.

01

Choose what to watch

A single file, a folder, or a wildcard. Tick Include subfolders to walk the tree below it. Include and exclude patterns sit under Advanced settings, so temporary files and caches stay out of the results.

02

Set how often

Every 15 minutes, hourly or daily, set per watch item, so a hosts file and a web root can run on different schedules.

03

Scan against the baseline

The baseline is the recorded state of the files a source watches. Each scan reports what has changed against it. Very large files are tracked by size, timestamps and permissions, so scans stay quick and predictable.

04

Deliver as events

Changes are reported as events, so they pass through the same pipeline stages as everything else and reach Splunk, a syslog SIEM, a Snare receiver, an NDJSON collector or an OpenTelemetry Collector over the transport you already use. See SIEM integrations.

05

Re-baseline after planned change

After a patch or a deployment, accept the current state as the new normal so the next scan starts clean. Re-baseline one watch item or all of them; either way the action is recorded in the tamper-evident audit log.

06

Nothing extra to buy

The agent entitlement in a DPLens licence covers every local source – Windows Event Log, log files and file integrity – plus every stage and destination. FIM is included.

Why scheduled scanning

Change detection built for critical files

DPLens scans each watch item on its schedule and reports the difference from the baseline. For the files that matter most, that gives you a clean, predictable signal.

  • Predictable load. Work happens at scan time, on paths you chose, so a busy server stays responsive.
  • One less agent. No separate FIM product to deploy, license and maintain alongside your log forwarder.
  • A clean signal for slow-moving files. Binaries, drivers, configuration and web content should change rarely and on a plan. A scan every 15 minutes or every hour catches unplanned change well inside a working day.
  • Watch lists managed centrally. DPLens Manager applies the same watch list to every server in scope and shows fleet health in one place. It is self-hosted, air-gap capable and included in every subscription.

What reaches your SIEM

What does a change event tell you?

Each watch item reports what changed against its baseline as an event tagged with the source's name or a tag you choose, such as "fim". The event passes through the same pipeline as your Windows event logs, so you can filter, enrich and mask it before it reaches the SIEM.

Before you build SIEM correlation searches, look at the real record: use Send test event from the source's row menu and watch Live stream with your destination selected. Live stream shows the exact bytes the destination receives.

Attributing a change to an account

To add who-made-the-change context, enable Windows object-access auditing (a SACL on the paths that matter) and collect the resulting Security log events, such as Event ID 4663, with a Windows Event Log source on the same agent. Your SIEM can then correlate the change report with the audit record of who wrote the file.

Configuration

An example watch list

Start from paths like these, set a schedule for each, and exclude temporary files and caches so the results stay meaningful.

Example paths to consider watching. These are examples, not a recommended baseline; your critical-file list comes from your own risk assessment.
Example pathWhy it mattersExample schedule
C:\Windows\System32\drivers\etc\hostsA favourite target for redirecting name resolutionEvery 15 min
C:\Windows\System32\drivers\*.sysKernel drivers change on patch day and almost never otherwiseHourly; re-baseline after patching
C:\inetpub\wwwroot\ with subfoldersWeb content and scripts, where a web shell would landEvery 15 min or hourly, excluding temp files
web.config and application configuration filesConnection strings, authentication and logging settingsHourly
Payment or line-of-business application foldersBinaries and libraries in the cardholder data environmentHourly or daily

Compliance

Supporting PCI DSS v4.0.1 requirement 11.5.2

Requirement 11.5.2 asks for a change-detection mechanism, such as file integrity monitoring, that alerts personnel to unauthorised modification of critical files (changes, additions and deletions) and performs critical-file comparisons at least once a week.

DPLens scans run every 15 minutes, hourly or daily, well inside the weekly minimum. The rest of the requirement is shared between DPLens and you:

  • DPLens provides the scheduled comparison against a baseline, change events delivered to your SIEM over the transport you choose (TLS, with certificate validation on by default, is recommended), and an audit-log record every time someone re-baselines.
  • You provide the list of critical files, the SIEM alerting that notifies personnel, and the process for investigating and responding to an alert.

DPLens supports the control; your organisation meets it, and your QSA decides. This is not legal or assessment advice. See DPLens and PCI DSS v4.0.1 for how the agent also supports the logging requirements in 10.2 to 10.5.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions buyers ask

What can DPLens watch?

A single file, a folder with or without its subfolders, or a wildcard, with include and exclude patterns to keep temporary files and caches out of the results. Each watch item has its own schedule: every 15 minutes, hourly or daily.

Does this make us compliant with PCI DSS 11.5.2?

It supports the control. Scans run far more often than the weekly minimum and changes reach your SIEM as events. You still define the critical files, configure alerting to personnel and run the response process, and your assessor makes the call.

Is FIM included in the licence?

Yes. The agent entitlement covers every local source, including file integrity, along with every stage, destination and the console. Only syslog and NetFlow receivers count as network sources.

What happens on patch day?

Expect the next scan to report the files the patch changed. Once you have reviewed them, re-baseline the affected watch items so the following scan starts clean. Each re-baseline is written to the audit log with the account that did it.

We build servers from a golden image. How do clones handle baselines?

A clone prepared with sysprep detects its new machine identity at first start, clears the image's file-integrity baselines along with its other working state, records an audit entry and baselines its own files.

Can we manage watch lists across many servers?

Yes. DPLens Manager provides central configuration, fleet health monitoring, deployment and upgrades. It is self-hosted, air-gap capable and included in every subscription. Agents can also be deployed with Group Policy, Intune or Configuration Manager.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.