Windows file integrity monitoring
Windows file integrity monitoring from the log agent you already run.
Watch critical files, folders and wildcards on a schedule, and send every change to your SIEM through the same pipeline as your Windows event logs. No second agent, no extra licence.
- Files, folders, wildcards
- Every 15 min, hourly or daily
- Re-baselines in the audit log
- PCI DSS v4.0.1 11.5.2
In short
DPLens adds Windows file integrity monitoring (FIM) to the log agent you already deploy: it scans the files, folders and wildcards you choose every 15 minutes, hourly or daily, compares them with a recorded baseline, and sends changes to your SIEM as events. Scans run far more often than the at-least-weekly comparison in PCI DSS v4.0.1 requirement 11.5.2.
How it works
How does file integrity monitoring work in DPLens?
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. File integrity is one of its five source types, beside Windows Event Log, log files, syslog and NetFlow. Each file-integrity source holds a list of watch items, and each watch item is a path and a schedule.
01
Choose what to watch
A single file, a folder, or a wildcard. Tick Include subfolders to walk the tree below it. Include and exclude patterns sit under Advanced settings, so temporary files and caches stay out of the results.
02
Set how often
Every 15 minutes, hourly or daily, set per watch item, so a hosts file and a web root can run on different schedules.
03
Scan against the baseline
The baseline is the recorded state of the files a source watches. Each scan reports what has changed against it. Very large files are tracked by size, timestamps and permissions, so scans stay quick and predictable.
04
Deliver as events
Changes are reported as events, so they pass through the same pipeline stages as everything else and reach Splunk, a syslog SIEM, a Snare receiver, an NDJSON collector or an OpenTelemetry Collector over the transport you already use. See SIEM integrations.
05
Re-baseline after planned change
After a patch or a deployment, accept the current state as the new normal so the next scan starts clean. Re-baseline one watch item or all of them; either way the action is recorded in the tamper-evident audit log.
06
Nothing extra to buy
The agent entitlement in a DPLens licence covers every local source – Windows Event Log, log files and file integrity – plus every stage and destination. FIM is included.
Why scheduled scanning
Change detection built for critical files
DPLens scans each watch item on its schedule and reports the difference from the baseline. For the files that matter most, that gives you a clean, predictable signal.
- Predictable load. Work happens at scan time, on paths you chose, so a busy server stays responsive.
- One less agent. No separate FIM product to deploy, license and maintain alongside your log forwarder.
- A clean signal for slow-moving files. Binaries, drivers, configuration and web content should change rarely and on a plan. A scan every 15 minutes or every hour catches unplanned change well inside a working day.
- Watch lists managed centrally. DPLens Manager applies the same watch list to every server in scope and shows fleet health in one place. It is self-hosted, air-gap capable and included in every subscription.
What reaches your SIEM
What does a change event tell you?
Each watch item reports what changed against its baseline as an event tagged with the source's name or a tag you choose, such as "fim". The event passes through the same pipeline as your Windows event logs, so you can filter, enrich and mask it before it reaches the SIEM.
Before you build SIEM correlation searches, look at the real record: use Send test event from the source's row menu and watch Live stream with your destination selected. Live stream shows the exact bytes the destination receives.
Attributing a change to an account
To add who-made-the-change context, enable Windows object-access auditing (a SACL on the paths that matter) and collect the resulting Security log events, such as Event ID 4663, with a Windows Event Log source on the same agent. Your SIEM can then correlate the change report with the audit record of who wrote the file.
Configuration
An example watch list
Start from paths like these, set a schedule for each, and exclude temporary files and caches so the results stay meaningful.
| Example path | Why it matters | Example schedule |
|---|---|---|
C:\Windows\System32\drivers\etc\hosts | A favourite target for redirecting name resolution | Every 15 min |
C:\Windows\System32\drivers\*.sys | Kernel drivers change on patch day and almost never otherwise | Hourly; re-baseline after patching |
C:\inetpub\wwwroot\ with subfolders | Web content and scripts, where a web shell would land | Every 15 min or hourly, excluding temp files |
web.config and application configuration files | Connection strings, authentication and logging settings | Hourly |
| Payment or line-of-business application folders | Binaries and libraries in the cardholder data environment | Hourly or daily |
Compliance
Supporting PCI DSS v4.0.1 requirement 11.5.2
Requirement 11.5.2 asks for a change-detection mechanism, such as file integrity monitoring, that alerts personnel to unauthorised modification of critical files (changes, additions and deletions) and performs critical-file comparisons at least once a week.
DPLens scans run every 15 minutes, hourly or daily, well inside the weekly minimum. The rest of the requirement is shared between DPLens and you:
- DPLens provides the scheduled comparison against a baseline, change events delivered to your SIEM over the transport you choose (TLS, with certificate validation on by default, is recommended), and an audit-log record every time someone re-baselines.
- You provide the list of critical files, the SIEM alerting that notifies personnel, and the process for investigating and responding to an alert.
DPLens supports the control; your organisation meets it, and your QSA decides. This is not legal or assessment advice. See DPLens and PCI DSS v4.0.1 for how the agent also supports the logging requirements in 10.2 to 10.5.
Secure by design
An agent you can defend in a security review.
FAQ
Questions buyers ask
What can DPLens watch?
A single file, a folder with or without its subfolders, or a wildcard, with include and exclude patterns to keep temporary files and caches out of the results. Each watch item has its own schedule: every 15 minutes, hourly or daily.
Does this make us compliant with PCI DSS 11.5.2?
It supports the control. Scans run far more often than the weekly minimum and changes reach your SIEM as events. You still define the critical files, configure alerting to personnel and run the response process, and your assessor makes the call.
Is FIM included in the licence?
Yes. The agent entitlement covers every local source, including file integrity, along with every stage, destination and the console. Only syslog and NetFlow receivers count as network sources.
What happens on patch day?
Expect the next scan to report the files the patch changed. Once you have reviewed them, re-baseline the affected watch items so the following scan starts clean. Each re-baseline is written to the audit log with the account that did it.
We build servers from a golden image. How do clones handle baselines?
A clone prepared with sysprep detects its new machine identity at first start, clears the image's file-integrity baselines along with its other working state, records an audit entry and baselines its own files.
Can we manage watch lists across many servers?
Yes. DPLens Manager provides central configuration, fleet health monitoring, deployment and upgrades. It is self-hosted, air-gap capable and included in every subscription. Agents can also be deployed with Group Policy, Intune or Configuration Manager.
Related
Where FIM fits
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.