File Integrity Monitoring
Also known as:FIM
File Integrity MonitoringMonitoringThe continuous observation of systems, identities, networks, and controls for relevant changes.: Detects unexpected changes to files, configurations, and system objects. This capability supports the early detectionDetectionThe capability to identify suspicious activity, attacks, or policy violations in time. of suspicious activity. Effective results require high-quality data sourcesData SourceA system, sensor, log, or repository that supplies data for security analysis and decisions., tuned detection logicDetection LogicRules, queries, models, and conditions used to identify suspicious behavior., triage, and continuous optimizationContinuous OptimizationOngoing tuning of rules, processes, and resources using measured operational results..
How it works and where it fits
File Integrity Monitoring connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.
Practical security relevance
Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.
Related concepts
- IntegrityIntegrityProperty ensuring that data is complete, accurate, and unaltered.: Property ensuring that data is complete, accurate, and unaltered.
- Endpoint Detection and ResponseEndpoint Detection and ResponseContinuously monitors endpoints and supports detection, investigation, and containment.: Continuously monitors endpoints and supports detection, investigation, and containment.
- Security Information and Event ManagementSecurity Information and Event ManagementCollects and correlates security events for monitoring, alerting, and evidence gathering.: Collects and correlates security events for monitoring, alerting, and evidence gathering.
- HardeningHardeningReduces the attack surface through secure configuration and the deactivation of unnecessary functions.: Reduces the attack surface through secure configuration and the deactivation of unnecessary functions.