Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Monitoring Critical Configuration Changes with Log360

Manage Engine
05/08/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Lock360. One of the primary functions of security operations is to keep the threats at bay. To do this, you need to monitor your network constantly and look for subtle signs of potential threats. Mapped to the initial access, defense evasion, and persistence attacking techniques, critical changes to security tools, firewalls, servers, and cloud platforms are one of the solid indicators of potential threats. Lock360 ManageEngine SIEM solution monitors and alerts you on the following things. Firstly, we've got firewall rule changes under which you can see reports for the addition, modification, and deletion of firewall rule. Here, you can see the precise time of when the rule was added and which device it originated from and the rule ID, the rule name, and the profile name. You will find all these details in the other reports as well pertaining to firewall rule changes. Next, we've got registry changes. This includes the creation or modification of registry values, insights on failed registry modifications, and failed registry permission changes. Critical information such as the user involved and the time of the changes is also highlighted. Here, you can see that it shows what exactly had been modified in the registry and also provides the previous value. Let's move on to router configuration changes. Here, we can see the router configuration changes report. It categorizes changes initiated from remote devices and shows change trends. Detailed insights include users who made the changes, the source, and the time of each modification across various devices like routers, switches, firewalls, across vendors like Cisco, SonicWall, and others. Now, let me take you to Cloud Security Plus, a component of Lock360, where we'll be looking at the cloud configuration changes report. Within the report, you'll find details such as the exact moment the configuration change occurred and the source that the change originated from, the event name, and which user made that change, and the source IP address. This detailed report breaks down a recent VPC deletion. We see who initiated it, the exact time, and the specific VPC removed. This report is crucial for maintaining a strong security posture in your cloud infrastructure, specifically for both AWS and Azure platforms. Now, going back to Event Log Analyzer, let's look at configuration changes to critical servers such as IIS web servers and others. The configuration reports include information about who made the changes, where they originated from, and when they occurred, and also the old values and new values. And that's not all. Lock360 also captures critical changes to system processes with its out-of-the-box correlation rules based on the MITRE ATT&CK Threat Modeling Framework. To conduct thorough investigation of these indicators and subsequent events stemming from them, invoke Incident Workbench of Lock360 and visualize the user accesses and activities post-event to validate threat condition. Get in touch with our technical experts to know more about Lock360's configuration change monitoring and optimizing it to your environment.

TL;DR

  • Log360 monitors critical configuration changes across firewalls, servers, network devices, and cloud platforms to detect potential security threats mapped to MITRE ATT&CK techniques for initial access, defense evasion, and persistence.
  • The solution provides detailed audit trails for firewall rule changes, registry modifications, router configurations, and cloud infrastructure changes in AWS and Azure, capturing who made changes, when, from where, and what specific values were modified.
  • Incident Workbench enables security teams to investigate suspicious configuration changes by visualizing user activities and access patterns post-event, using out-of-the-box correlation rules based on the MITRE ATT&CK framework to validate threat conditions.

Summary

This demonstration showcases how ManageEngine Log360 enables security operations teams to monitor and respond to critical configuration changes across enterprise infrastructure. The video walks through Log360's capabilities for tracking unauthorized modifications to firewalls, routers, servers, registries, and cloud platforms—changes that often signal initial access attempts, defense evasion tactics, or persistence mechanisms aligned with the MITRE ATT&CK framework. Key monitoring areas include firewall rule additions and deletions with complete audit trails, Windows registry modifications with before-and-after values, router configuration changes across multi-vendor environments including Cisco and SonicWall, and cloud infrastructure changes in AWS and Azure through the integrated Cloud Security Plus component. The solution provides detailed forensic data for each change event, including the user responsible, source device or IP address, precise timestamps, and specific configuration values modified. For investigation workflows, Log360's Incident Workbench allows analysts to visualize user activities and access patterns following suspicious configuration changes, enabling validation of potential threat conditions through correlation rules based on MITRE ATT&CK techniques.

Chapters

0:00 - Introduction to Configuration Monitoring
0:45 - Firewall Rule Change Tracking
1:10 - Registry Modification Monitoring
1:37 - Router Configuration Changes
2:03 - Cloud Infrastructure Monitoring
2:48 - Server Configuration Tracking
3:10 - MITRE ATT&CK Correlation
3:22 - Incident Investigation Workflow

Key Quotes

0:24 "Mapped to the initial access, defense evasion, and persistence attacking techniques, critical changes to security tools, firewalls, servers, and cloud platforms are one of the solid indicators of potential threats."
1:56 "Detailed insights include users who made the changes, the source, and the time of each modification across various devices like routers, switches, firewalls, across vendors like Cisco, SonicWall, and others."
3:10 "Lock360 also captures critical changes to system processes with its out-of-the-box correlation rules based on the MITRE ATT&CK Threat Modeling Framework."

Categories:
  • » Cybersecurity » Network Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Cloud Security
  • Network Security
  • Compliance & Governance
  • Demo
  • Technical Deep Dive
  • SIEM
  • Configuration Change Monitoring
  • MITRE ATT&CK Framework
  • Firewall Management
  • Network Device Monitoring
  • Threat Detection
  • Incident Response
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Monitoring Critical Configuration Changes with Log360

              Industry Events (Sponsor Hosted)

              • Aug
                13

                Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                08/13/202612:00 PM ET
                • Aug
                  19

                  Becoming Agent Ready with Cyera: Essential Strategies and Insights

                  08/19/202612:00 PM ET
                  More events

                  Upcoming Webinar Calendar

                  • 08/13/2026
                    12:00 PM
                    08/13/2026
                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                    https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                  • 08/19/2026
                    12:00 PM
                    08/19/2026
                    Becoming Agent Ready with Cyera: Essential Strategies and Insights
                    https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                  • 09/02/2026
                    12:00 PM
                    09/02/2026
                    Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                    https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                  • 09/30/2026
                    04:00 AM
                    09/30/2026
                    AI Command Center: Optimizing Visibility and Control in Your Operations
                    https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                  • 11/19/2026
                    01:00 PM
                    11/19/2026
                    360View: Govern, Secure & Recover Your Microsoft 365 Environment
                    https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                  Truth in IT
                  • Sponsor
                  • About Us
                  • Terms of Service
                  • Privacy Policy
                  • Contact Us
                  • Preference Management
                  Desktop version
                  Standard version