Change Auditor uses FSDriver.sys to capture file access events and filter them based on the File Protection Templates configured for this location.
Pre-Requisite:
Process:
How to confirm that the configuration is applied:
ID: 13458 Time: 5/30/16 19:14:44.649
Level: INFO
Thread: 4320
Logger: CAAD.Agent.CFileSystemSink
File: FileSystemSink.cpp
Function: CFileSystemSink::UpdateConfiguration
Line: 279
Message: ITFA Plug-in protection config: protect="true" allow="false" location-protection-types="0" applies-to="FD" access-types="CD">
Restrictions on File Protection:
How to Report on protection violation:
© ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center