Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Monitoring Critical Configuration Changes with Log360

Manage Engine
05/08/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Lock360. One of the primary functions of security operations is to keep the threats at bay. To do this, you need to monitor your network constantly and look for subtle signs of potential threats. Mapped to the initial access, defense evasion, and persistence attacking techniques, critical changes to security tools, firewalls, servers, and cloud platforms are one of the solid indicators of potential threats. Lock360 ManageEngine SIEM solution monitors and alerts you on the following things. Firstly, we've got firewall rule changes under which you can see reports for the addition, modification, and deletion of firewall rule. Here, you can see the precise time of when the rule was added and which device it originated from and the rule ID, the rule name, and the profile name. You will find all these details in the other reports as well pertaining to firewall rule changes. Next, we've got registry changes. This includes the creation or modification of registry values, insights on failed registry modifications, and failed registry permission changes. Critical information such as the user involved and the time of the changes is also highlighted. Here, you can see that it shows what exactly had been modified in the registry and also provides the previous value. Let's move on to router configuration changes. Here, we can see the router configuration changes report. It categorizes changes initiated from remote devices and shows change trends. Detailed insights include users who made the changes, the source, and the time of each modification across various devices like routers, switches, firewalls, across vendors like Cisco, SonicWall, and others. Now, let me take you to Cloud Security Plus, a component of Lock360, where we'll be looking at the cloud configuration changes report. Within the report, you'll find details such as the exact moment the configuration change occurred and the source that the change originated from, the event name, and which user made that change, and the source IP address. This detailed report breaks down a recent VPC deletion. We see who initiated it, the exact time, and the specific VPC removed. This report is crucial for maintaining a strong security posture in your cloud infrastructure, specifically for both AWS and Azure platforms. Now, going back to Event Log Analyzer, let's look at configuration changes to critical servers such as IIS web servers and others. The configuration reports include information about who made the changes, where they originated from, and when they occurred, and also the old values and new values. And that's not all. Lock360 also captures critical changes to system processes with its out-of-the-box correlation rules based on the MITRE ATT&CK Threat Modeling Framework. To conduct thorough investigation of these indicators and subsequent events stemming from them, invoke Incident Workbench of Lock360 and visualize the user accesses and activities post-event to validate threat condition. Get in touch with our technical experts to know more about Lock360's configuration change monitoring and optimizing it to your environment.

TL;DR

  • Log360 monitors critical configuration changes across firewalls, servers, network devices, and cloud platforms to detect potential security threats mapped to MITRE ATT&CK techniques for initial access, defense evasion, and persistence.
  • The solution provides detailed audit trails for firewall rule changes, registry modifications, router configurations, and cloud infrastructure changes in AWS and Azure, capturing who made changes, when, from where, and what specific values were modified.
  • Incident Workbench enables security teams to investigate suspicious configuration changes by visualizing user activities and access patterns post-event, using out-of-the-box correlation rules based on the MITRE ATT&CK framework to validate threat conditions.

Summary

This demonstration showcases how ManageEngine Log360 enables security operations teams to monitor and respond to critical configuration changes across enterprise infrastructure. The video walks through Log360's capabilities for tracking unauthorized modifications to firewalls, routers, servers, registries, and cloud platforms—changes that often signal initial access attempts, defense evasion tactics, or persistence mechanisms aligned with the MITRE ATT&CK framework. Key monitoring areas include firewall rule additions and deletions with complete audit trails, Windows registry modifications with before-and-after values, router configuration changes across multi-vendor environments including Cisco and SonicWall, and cloud infrastructure changes in AWS and Azure through the integrated Cloud Security Plus component. The solution provides detailed forensic data for each change event, including the user responsible, source device or IP address, precise timestamps, and specific configuration values modified. For investigation workflows, Log360's Incident Workbench allows analysts to visualize user activities and access patterns following suspicious configuration changes, enabling validation of potential threat conditions through correlation rules based on MITRE ATT&CK techniques.

Chapters

0:00 - Introduction to Configuration Monitoring
0:45 - Firewall Rule Change Tracking
1:10 - Registry Modification Monitoring
1:37 - Router Configuration Changes
2:03 - Cloud Infrastructure Monitoring
2:48 - Server Configuration Tracking
3:10 - MITRE ATT&CK Correlation
3:22 - Incident Investigation Workflow

Key Quotes

0:24 "Mapped to the initial access, defense evasion, and persistence attacking techniques, critical changes to security tools, firewalls, servers, and cloud platforms are one of the solid indicators of potential threats."
1:56 "Detailed insights include users who made the changes, the source, and the time of each modification across various devices like routers, switches, firewalls, across vendors like Cisco, SonicWall, and others."
3:10 "Lock360 also captures critical changes to system processes with its out-of-the-box correlation rules based on the MITRE ATT&CK Threat Modeling Framework."

Categories:
  • » Cybersecurity » Network Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Cloud Security
  • Network Security
  • Compliance & Governance
  • Demo
  • Technical Deep Dive
  • SIEM
  • Configuration Change Monitoring
  • MITRE ATT&CK Framework
  • Firewall Management
  • Network Device Monitoring
  • Threat Detection
  • Incident Response
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Monitoring Critical Configuration Changes with Log360

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                Accelerating Through AI: A Dynamic Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-through-ai-a-dynamic-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                Preventing Your AI from Turning Against You: Essential Strategies
                https://www.truthinit.com/index.php/channel/2021/preventing-your-ai-from-turning-against-you-essential-strategies/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Empowering Trust Through Action and Engagement
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-empowering-trust-through-action-and-engagement/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Quality Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-quality-security-team-for-unmatched-defense/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  Accelerating Through AI: A Dynamic Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version