ื•ื•ื‘ื™ื ืจ ื‘ื ื•ืฉื Quest Change Auditor - ืคืชืจื•ืŸ ืœื‘ื™ืงื•ืจืช ืื™ืจื•ืขื™ ืื‘ื˜ื—ืช ืžื™ื“ืข

ื•ื•ื‘ื™ื ืจ ื‘ื ื•ืฉื Quest Change Auditor - ืคืชืจื•ืŸ ืœื‘ื™ืงื•ืจืช ืื™ืจื•ืขื™ ืื‘ื˜ื—ืช ืžื™ื“ืข

ืœืคื ื™ ืžืกืคืจ ืฉื ื™ื, ื›ืฉื”ืชื—ืœื ื• ืœื™ื™ืฉื ืืช Change Auditor ื‘ื‘ื ืง ืื—ื“, ื”ื‘ื—ื ื• ื‘ืžื’ื•ื•ืŸ ืขืฆื•ื ืฉืœ ืกืงืจื™ืคื˜ื™ื ืฉืœ PowerShell ืฉื‘ื™ืฆืขื• ื‘ื“ื™ื•ืง ืืช ืื•ืชื” ืžืฉื™ืžืช ื‘ื™ืงื•ืจืช, ืืš ืชื•ืš ืฉื™ืžื•ืฉ ื‘ืฉื™ื˜ื” ืžืื•ืœืชืจืช. ื”ืจื‘ื” ื–ืžืŸ ืขื‘ืจ ืžืื–, ื”ืœืงื•ื— ืขื“ื™ื™ืŸ ืžืฉืชืžืฉ ื‘- Change Auditor ื•ื–ื•ื›ืจ ืืช ื”ืชืžื™ื›ื” ื‘ื›ืœ ื”ืชืกืจื™ื˜ื™ื ื”ืืœื” ื›ืžื• ื—ืœื•ื ืจืข. ื”ื—ืœื•ื ื”ื–ื” ื™ื›ื•ืœ ื”ื™ื” ืœื”ืคื•ืš ืœืกื™ื•ื˜ ืื ื”ืื“ื ืฉื˜ื™ืคืœ ื‘ืชืกืจื™ื˜ื™ื ื‘ืื“ื ืื—ื“ ืคืฉื•ื˜ ื”ื™ื” ืžืชืคื˜ืจ, ืฉื•ื›ื— ื‘ื—ื•ืคื–ื” ืœื”ืขื‘ื™ืจ ื™ื“ืข ืกื•ื“ื™. ืฉืžืขื ื• ืžืขืžื™ืชื™ื ืฉืžืงืจื™ื ื›ืืœื” ืงืจื• ืคื” ื•ืฉื ื•ื–ื” ื”ื‘ื™ื ืื– ื›ืื•ืก ืžืฉืžืขื•ืชื™ ืœืขื‘ื•ื“ื” ืฉืœ ืžื—ืœืงืช ืื‘ื˜ื—ืช ืžื™ื“ืข. ื‘ืžืืžืจ ื–ื”, ื ื“ื‘ืจ ืขืœ ื”ื™ืชืจื•ื ื•ืช ื”ืขื™ืงืจื™ื™ื ืฉืœ Change Auditor ื•ื ื›ืจื™ื– ืขืœ ืกืžื™ื ืจ ืžืงื•ื•ืŸ ื‘-29 ื‘ื™ื•ืœื™ ืขืœ ื›ืœื™ ืื•ื˜ื•ืžืฆื™ื™ืช ื‘ื™ืงื•ืจืช ื–ื”. ืžืชื—ืช ืœื’ื–ืจื” ื›ืœ ื”ืคืจื˜ื™ื.

ืฆื™ืœื•ื ื”ืžืกืš ืœืžืขืœื” ืžืฆื™ื’ ืืช ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ IT Security Search ืขื ืกืจื’ืœ ื—ื™ืคื•ืฉ ื“ืžื•ื™ ื’ื•ื’ืœ, ื‘ื• ื ื•ื— ืœืžื™ื™ืŸ ืื™ืจื•ืขื™ื ืž- Change Auditor ื•ืœื”ื’ื“ื™ืจ ืชืฆื•ื’ื•ืช.

Change Auditor ื”ื•ื ื›ืœื™ ืจื‘ ืขื•ืฆืžื” ืœื‘ื™ืงื•ืจืช ืฉื™ื ื•ื™ื™ื ื‘ืชืฉืชื™ืช Microsoft, ืžืขืจื›ื™ ื“ื™ืกืงื™ื ื•-VMware. ื‘ื™ืงื•ืจืช ื ืชืžื›ืช: AD, Azure AD, SQL Server, Exchange, Exchange Online, Sharepoint, Sharepoint Online, Windows File Server, OneDrive for Business, Skype for Business, VMware, NetApp, EMC, FluidFS. ื™ืฉื ื ื“ื•ื—ื•ืช ืžื•ืชืงื ื™ื ืžืจืืฉ ืœืขืžื™ื“ื” ื‘ืชืงื ื™ GDPR, SOX, PCI, HIPAA, FISMA, GLBA.

ืžื“ื“ื™ื ื ืืกืคื™ื ืžืฉืจืชื™ Windows ื‘ืฆื•ืจื” ืžื‘ื•ืกืกืช ืกื•ื›ืŸ, ื”ืžืืคืฉืจืช ื‘ื™ืงื•ืจืช ื‘ืืžืฆืขื•ืช ืื™ื ื˜ื’ืจืฆื™ื” ืขืžื•ืงื” ืœืฉื™ื—ื•ืช ื‘ืชื•ืš AD, ื•ื›ืคื™ ืฉื”ืกืคืง ืขืฆืžื• ื›ื•ืชื‘, ืฉื™ื˜ื” ื–ื• ืžื–ื”ื” ืฉื™ื ื•ื™ื™ื ืืคื™ืœื• ื‘ืงื‘ื•ืฆื•ืช ืžืงื•ื ื ื•ืช ืขืžื•ืงื•ืช ื•ืžื›ื ื™ืกื” ืคื—ื•ืช ืขื•ืžืก ืžืืฉืจ ื‘ืขืช ื›ืชื™ื‘ื”, ืงืจื™ืื” ื• ืื—ื–ื•ืจ ื™ื•ืžื ื™ื (ื›ื›ื” ื”ื ืขื•ื‘ื“ื™ื ืคืชืจื•ื ื•ืช ืžืชื—ืจื™ื). ืืชื” ื™ื›ื•ืœ ืœื‘ื“ื•ืง ืืช ื–ื” ื‘ืขื•ืžืก ื’ื‘ื•ื”. ื›ืชื•ืฆืื” ืžืฉื™ืœื•ื‘ ื‘ืจืžื” ื ืžื•ื›ื” ื›ื–ื•, ื‘-Quest Change Auditor ืืชื” ื™ื›ื•ืœ ืœื”ื˜ื™ืœ ื•ื˜ื• ืขืœ ืฉื™ื ื•ื™ื™ื ืžืกื•ื™ืžื™ื ืขื‘ื•ืจ ืื•ื‘ื™ื™ืงื˜ื™ื ืžืกื•ื™ืžื™ื, ืืคื™ืœื• ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ื‘ืจืžืช Enterprise Admin. ื›ืœื•ืžืจ, ื”ื’ืŸ ืขืœ ืขืฆืžืš ืžืคื ื™ ืžื ื”ืœื™ AD ื–ื“ื•ื ื™ื™ื.

ื‘-Change Auditor, ื›ืœ ื”ืฉื™ื ื•ื™ื™ื ืžื ื•ืจืžืœื™ื ืœืกื•ื’ 5W - ืžื™, ืžื”, ืื™ืคื”, ืžืชื™, ืชื—ื ืช ืขื‘ื•ื“ื” (ืžื™, ืžื”, ืื™ืคื”, ืžืชื™ ื•ื‘ืื™ื–ื” ืชื—ื ืช ืขื‘ื•ื“ื”). ืคื•ืจืžื˜ ื–ื” ืžืืคืฉืจ ืœืš ืœืื—ื“ ืื™ืจื•ืขื™ื ืฉื”ืชืงื‘ืœื• ืžืžืงื•ืจื•ืช ืฉื•ื ื™ื.

ื‘-2 ื‘ื™ื•ื ื™ 2020, ืฉื•ื—ืจืจื” ื’ืจืกื” ื—ื“ืฉื” ืฉืœ Change Auditor - 7.1. ื™ืฉ ืœื• ืืช ื”ืฉื™ืคื•ืจื™ื ื”ืขื™ืงืจื™ื™ื ื”ื‘ืื™ื:

  • ื–ื™ื”ื•ื™ ืื™ื•ื ืžืขื‘ืจ-ื”ื›ืจื˜ื™ืก (ื–ื™ื”ื•ื™ ื›ืจื˜ื™ืกื™ Kerberos ืขื ืชืืจื™ืš ืชืคื•ื’ื” ื”ื—ื•ืจื’ ืžืžื“ื™ื ื™ื•ืช ื”ื“ื•ืžื™ื™ืŸ, ืžื” ืฉืขืฉื•ื™ ืœื”ืฆื‘ื™ืข ืขืœ ื”ืชืงืคืช ื›ืจื˜ื™ืก ื’ื•ืœื“ืŸ ืคื•ื˜ื ืฆื™ืืœื™ืช);
  • ื‘ื™ืงื•ืจืช ืฉืœ ืื™ืžื•ืชื™ NTLM ืžื•ืฆืœื—ื™ื ื•ืœื ืžื•ืฆืœื—ื™ื (ืชื•ื›ืœ ืœืงื‘ื•ืข ืืช ื’ืจืกืช NTLM ื•ืœื”ื•ื“ื™ืข โ€‹โ€‹ืขืœ ื™ื™ืฉื•ืžื™ื ื”ืžืฉืชืžืฉื™ื ื‘-v1);
  • ื‘ื™ืงื•ืจืช ืฉืœ ืื™ืžื•ืชื™ Kerberos ืžื•ืฆืœื—ื™ื ื•ืœื ืžื•ืฆืœื—ื™ื;
  • ืคืจื™ืกืช ืกื•ื›ื ื™ ื‘ื™ืงื•ืจืช ื‘ื™ืขืจ AD ืกืžื•ืš.

ื•ื•ื‘ื™ื ืจ ื‘ื ื•ืฉื Quest Change Auditor - ืคืชืจื•ืŸ ืœื‘ื™ืงื•ืจืช ืื™ืจื•ืขื™ ืื‘ื˜ื—ืช ืžื™ื“ืข
ืฆื™ืœื•ื ื”ืžืกืš ืžืฆื™ื’ ืื™ื•ื ืžื–ื•ื”ื” ืขื ืชืงื•ืคื” ืืจื•ื›ื” ืฉืœ ืชื•ืงืฃ ืฉืœ ื›ืจื˜ื™ืก Kerberos.

ื™ื—ื“ ืขื ืžื•ืฆืจ ื ื•ืกืฃ ืžื‘ื™ืช Quest - On Demand Audit, ื ื™ืชืŸ ืœื‘ืงืจ ืกื‘ื™ื‘ื•ืช ื”ื™ื‘ืจื™ื“ื™ื•ืช ืžืžืžืฉืง ื™ื—ื™ื“ ื•ืœื ื˜ืจ ื›ื ื™ืกื•ืช ื‘-AD, Azure AD ื•ืฉื™ื ื•ื™ื™ื ื‘-Office 365.

ื™ืชืจื•ืŸ ื ื•ืกืฃ ืฉืœ Change Auditor ื”ื•ื ื”ืืคืฉืจื•ืช ืœืื™ื ื˜ื’ืจืฆื™ื” ืžื—ื•ืฅ ืœืงื•ืคืกื” ืขื ืžืขืจื›ืช SIEM ื™ืฉื™ืจื•ืช ืื• ื“ืจืš ืžื•ืฆืจ ืื—ืจ ืฉืœ Quest - InTrust. ืื ืชื’ื“ื™ืจ ืื™ื ื˜ื’ืจืฆื™ื” ื›ื–ื•, ืชื•ื›ืœ ืœื‘ืฆืข ืคืขื•ืœื•ืช ืื•ื˜ื•ืžื˜ื™ื•ืช ืœื“ื™ื›ื•ื™ ื”ืชืงืคื” ื“ืจืš InTrust, ื•ื‘ืื•ืชื” Elastic Stack ืชื•ื›ืœ ืœื”ื’ื“ื™ืจ ืชืฆื•ื’ื•ืช ื•ืœืชืช ื’ื™ืฉื” ืœืขืžื™ืชื™ื ืœืฆืคื™ื™ื” ื‘ื ืชื•ื ื™ื ื”ื™ืกื˜ื•ืจื™ื™ื.

ื•ื•ื‘ื™ื ืจ ื‘ื ื•ืฉื Quest Change Auditor - ืคืชืจื•ืŸ ืœื‘ื™ืงื•ืจืช ืื™ืจื•ืขื™ ืื‘ื˜ื—ืช ืžื™ื“ืข

ื›ื“ื™ ืœืœืžื•ื“ ืขื•ื“ ืขืœ Change Auditor, ืื ื• ืžื–ืžื™ื ื™ื ืื•ืชืš ืœื”ืฉืชืชืฃ ื‘ืกืžื™ื ืจ ื”ืžืงื•ื•ืŸ, ืฉื™ืชืงื™ื™ื ื‘-29 ื‘ื™ื•ืœื™ ื‘ืฉืขื” 11:XNUMX ืœืคื™ ืฉืขื•ืŸ ืžื•ืกืงื‘ื”. ืœืื—ืจ ื”ื•ื•ื‘ื™ื ืจ ืชื•ื›ืœ ืœืฉืื•ืœ ื›ืœ ืฉืืœื” ืฉืชื”ื™ื” ืœืš.

ื”ืจืฉืžื” ืœืกืžื™ื ืจ ื”ืžืงื•ื•ืŸ

ืžืืžืจื™ื ื ื•ืกืคื™ื ืขืœ ืคืชืจื•ื ื•ืช ืื‘ื˜ื—ื” ืฉืœ Quest:

ืžื™ ืขืฉื” ืืช ื–ื”? ืื ื• ืขื•ืฉื™ื ืื•ื˜ื•ืžืฆื™ื” ืฉืœ ื‘ื™ืงื•ืจืช ืื‘ื˜ื—ืช ืžื™ื“ืข

ืžืขืงื‘ ืื—ืจ ืžื—ื–ื•ืจ ื”ื—ื™ื™ื ืฉืœ ืžืฉืชืžืฉื™ื ืœืœื ืคืœื™ื™ืจ ืื• ืกืจื˜ ื“ื‘ื™ืง

ืื™ืœื• ื“ื‘ืจื™ื ืฉื™ืžื•ืฉื™ื™ื ื ื™ืชืŸ ืœื—ืœืฅ ืžื”ื™ื•ืžื ื™ื ืฉืœ ืชื—ื ืช ืขื‘ื•ื“ื” ืžื‘ื•ืกืกืช Windows?

ื ื™ืชืŸ ืœื”ื’ื™ืฉ ื‘ืงืฉื” ืœื™ื™ืขื•ืฅ, ื”ืคืฆื” ืื• ืคืจื•ื™ืงื˜ ืคื™ื™ืœื•ื˜ ื“ืจืš ื˜ื•ืคืก ืžืฉื•ื‘ ื‘ืืชืจ ืฉืœื ื•. ื™ืฉ ื’ื ืชื™ืื•ืจื™ื ืฉืœ ืคืชืจื•ื ื•ืช ืžื•ืฆืขื™ื.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”