How to Detect File Changes in a Shared Folder
Native Auditing vs. Netwrix Auditor for Windows File Servers
- Navigate to the file share, right-click it and select "Properties" → "Security" tab → "Advanced" button → "Auditing" tab → Click "Add" button Select Principal: "Everyone"; Select Type: "All"; Select Applies to: "This folder, subfolders and files"; Select the following "Advanced Permissions": сreate files/write data, сreate folders/append data, write attributes, write extended attributes.
- Run gpedit.msc, configure Default Domain Policy → Computer Configuration → Policies → Windows Settings → Security Settings → Local Policies → Audit Policy → Audit object access → Define "Success and Failures". In the "Advanced Audit Policy Configuration" adjust Audit File System → Define "Success and Failures" and Audit Handle Manipulation → Define "Success and Failures".
- Go to Event Log and set "Maximum security log size" to 1gb, "Retention method for Security log" to "Overwrite events as needed".
- Open "Event viewer" and search Security log for event id 4656 with "File System" or "Removable Storage" task category and with "Accesses: WriteData" string. "Subject Security ID" will show you who changed the file.
- Run Netwrix Auditor, navigate to Reports → File Servers → File Servers Activity → Select “File Server Changes” report → View.
Automate Auditing of File Changes to Quickly Spot Malicious Modifications
File changes in a shared folder, such as the deletion or relocation of files, can lead to information loss or even leaks of sensitive data — which in turn can result in reduced revenue, legal penalties and damage to the organization’s reputation. Therefore, IT pros need to monitor file changes in shared folders on Windows-based file servers. Comprehensive continuous monitoring enables IT staff to spot every suspicious file change in a timely manner and get the actionable details required for security investigations.
Netwrix Auditor for Windows File Servers enables you to monitor file changes across your Windows-based file servers. The application performs file change monitoring and delivers reports with all the critical who, what, where and when details. Google-like, interactive data search gives you the flexibility to find detailed information on particular users, such as all the files they have touched. This feature is particularly useful when it comes to investigating suspicious file activity, such as all file changes in the Accounting folder made by a particular HR employee.