SECagent

When Do I Need SECagent?

The short answer is that the SECagent is not required unless the system or device you need to monitor is unable to send events one of the numerous protocols typically used by network management platforms.  Most network security devices as well as Linux/Unix systems are typically able to send events; however, most other environments are not.  If one of these protocols is available to send events, then SECcollector is able to receive these real-time events directly. Otherwise, SECagent is needed.

cible_secagent-500x500_20260211_180347_213

Actively Retrieve Events

SECagent actively captures event data from systems that cannot send it, which ensures that real-time analysis is complete comprehensive.  This is an important issue most organizations because not all systems devices on the network are able to send their event data to either a central or a distributed repository on their own.  While some systems devices can send events to a predetermined location on the network, there are many which cannot fulfill this requirement. This can create an important hole in a comprehensive network infrastructure security management system.  To assess fully the state of the network the systems devices deployed all event data must be available fully analyzed.

SECagent fills this gap is able to get event data from sources that are unable to send them. It will fetch, watch, pull, send this data to SECcollect on the fly.  SECagent is able to watch file systems, Windows events, data files, folders, registry keys Active Directory events.

This product ensures that all events, whatever the platform, are available a comprehensive network infrastructure security management real-time analysis as well as retrospective analysis.

SECNOLOGY_SECagent_features
SECagent can

Manage control file folder integrity

Manage user rights access privileges on files folders

Audit in real-time user activity on targeted files folders

Audit in real-time access changes to Active Directory


With SECagent Find

All the systems to which a specific user is connected

The users who connected to a specific system in a certain time frame

All the changes that occurred to group members in Active Directory

The changes in users accounts

All read access to a file or group of files on a critical server

Ensure Data Availability

As SECagent retrieves event data, it can also send the same event to several IP addresses simultaneously to prevent any data loss to guarantee the data’s availability. Communications between SECcollect SECagent are encrypted SSL encapsulated.

Real-Time Monitoring of Event Logs Registry Keys

A stard feature in SECagent, the Event Viewer transmits all events to SECcollect in Real-Time. This also happens when the value of a Registry Key is changed.

Advanced Features

SECNOLOGY_SECagent_features_scan

Users Rights Privilege Management Files Folders

Respecting Data Governance requires that IT Security Managers know what rights privileges users or groups of users are assigned to files folders on their critical servers.  This allows them to correct configuration mistakes or to forbid unauthorized updates, whether the changes are accidental or fraudulent, to apply the correct changes actions immediately.  SECagent allows the audit of all targeted servers enables the monitoring of user rights privileges.

A scheduled map of these rights can be generated automatically, on a schedule or on a rights change event.  In parallel, an alert can be sent to Administrators Managers with the details.

Real-Time Monitoring of Users Activity on Files Folders

IT Security Managers are interested in knowing which users accessed, read, modified or deleted a specific file or group of files or a folder when.  To answer all these questions, SECNOLOGY developed a low-level driver to intercept all types of accesses actions on system resources.  With this driver SECagent scans audits in real-time all user activity on the targeted servers /or workstations.  All events are forwarded in real-time to SECcollect duly recorded.

File Integrity Management

Any event related to adding, changing or deleting a file, a group of files, a folder, a group of folders or even a security or network device configuration is immediately captured by SECagent forwarded in real-time to SECcollect.  SECmanage also provides file integrity management independently.

The combination of both SECagent SECmanage guaranties the integrity of a remote target by detecting any change on that target triggering automatic recovery of that target. Whatever the change, enforce the reference image in production.

LDAP AD Audit Real-Time Monitoring

Use SECagent’s advanced features to monitor all operations affecting Active Director or LDAP.

SECagent performs real-time monitoring in many situations, tracking:

 All the systems to which a user connects
The users who connect to a specific system
The changes applied to a group in Active Directory
 All the changes applied to Active Directory objects
 All the changes applied to Active Directory services
The changes applied to user accounts in Active Directory

A good example is a Web site. Should you decide to protect your Web site by keeping an image of the site as a reference somewhere on the network. Then, in case of any change to the Web site, SECNOLOGY will automatically detect the change restore the site the reference.  This will not protect your web site from attack, but it will definitely prevent the Web site from being corrupted!

SECNOLOGY_SECagent_speedometer

How to ensure all events ?

SECagent ensures that all events, whatever the platform, are available a comprehensive network infrastructure security management real-time analysis as well as retrospective analysis

CASE STUDIES

FINANCIAL

PUBLIC ENTERPRISE

RETAIL

AIRPORT