Skip to content

Commit f5831d9

Browse files
committed
test restruture of threatprevention
1 parent 0106cb3 commit f5831d9

25 files changed

+1219
-111
lines changed

docs/threatprevention/7.4/index.md

Lines changed: 27 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,27 @@
1-
# Threat Prevention 7.4
1+
# Netwrix Threat Prevention 7.4
2+
3+
Netwrix Threat Prevention safeguards organizations from internal and external threats by acting like a firewall around critical systems and applications: Active Directory, Exchange, and file systems. It empowers organizations to overcome limitations in native Windows logging and security controls.
4+
5+
## Key Features
6+
7+
- **Active Monitoring** – Intercepts critical activity at the source and actively monitors user behavior
8+
- **Proactive Remediation** – Automatically blocks suspicious activities and compromised accounts
9+
- **Real-time Alerts** – Provides inspection, alerting, and policy enforcement
10+
- **Comprehensive Audit Trail** – Detailed records of every change, access, and authentication
11+
- **Third-party Integration** – Seamless SIEM dashboard integration
12+
- **Modern Architecture** – FIPS 140-2 compliant design
13+
14+
## Quick Start
15+
16+
- [Getting Started](/docs/threatprevention/7.4/threatprevention/gettingstarted.md)
17+
- [System Requirements](/docs/threatprevention/7.4/threatprevention/requirements/overview.md)
18+
- [Installation Overview](/docs/threatprevention/7.4/threatprevention/install/overview.md)
19+
- [Product Overview](/docs/threatprevention/7.4/threatprevention/overview.md)
20+
21+
## Key Sections
22+
23+
- **[Administration](/docs/threatprevention/7.4/threatprevention/admin/overview.md)** - Agent management, policies, and configuration
24+
- **[Solutions](/docs/threatprevention/7.4/threatprevention/solutions/overview.md)** - Active Directory, Exchange, File System, and LDAP protection
25+
- **[Reporting](/docs/threatprevention/7.4/threatprevention/reportingmodule/overview.md)** - Investigations and analytics
26+
- **[SIEM Integration](/docs/threatprevention/7.4/threatprevention/siemdashboard/overview.md)** - QRadar and Splunk dashboards
27+
- **[Troubleshooting](/docs/threatprevention/7.4/threatprevention/troubleshooting/overview.md)** - Common issues and solutions

docs/threatprevention/7.4/threatprevention/admin/templates/folder/domainpersistence.md

Lines changed: 0 additions & 9 deletions
This file was deleted.

docs/threatprevention/7.4/threatprevention/admin/templates/folder/ldap.md renamed to docs/threatprevention/7.4/threatprevention/admin/templates/folder/infrastructure-templates.md

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,8 @@
1-
# LDAP Folder Templates
1+
# Infrastructure Templates
2+
3+
This section contains templates for monitoring and protecting infrastructure components.
4+
5+
## LDAP Monitoring {#ldap}
26

37
The LDAP folder contains the following templates:
48

@@ -9,3 +13,12 @@ The LDAP folder contains the following templates:
913
| LDAP: Sensitive Groups | This policy will detect LDAP queries targeting sensitive groups, such as Domain Admins, Enterprise Admins, and Schema Admins. Add to and delete from this list of groups in the LDAP Query filter per specific requirements | None |
1014
| LDAP: Sensitive SPNs | This policy will detect LDAP queries targeting sensitive Service Principal Names, such as Exchange and SQL Servers. Add to and delete from this list of SPNs in the LDAP Query filter per specific requirements | None |
1115
| LDAP: Service Principal Names | Detects attempts to obtain a list of SPN values | None |
16+
17+
## Threat Manager Integration {#threat-manager}
18+
19+
The Threat Manager folder contains the following templates:
20+
21+
| Template | Description | TAGS |
22+
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------- |
23+
| Threat Manager for AD | This is the recommended policy for sending AD Events captured by Threat Prevention to Threat Manager. This policy includes: Authentication Monitoring, Active Directory Changes, AD Replication Monitoring, and LSASS Guardian - Monitor. | - Threat Manager - NEW v6.1 TEMPLATES |
24+
| Threat Manager for AD LDAP | This is the recommended policy for sending LDAP events captured by Threat Prevention to Threat Manager for detecting signature queries of LDAP reconnaissance tools. Policy 1: Suspicious Queries Policy 2: Suspicious Attributes Returned | - Threat Manager - NEW v7.1 TEMPLATES |
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
# Microsoft Platform Templates
2+
3+
This section contains templates for monitoring and protecting Microsoft platform components.
4+
5+
## DNS Monitoring {#dns}
6+
7+
The **Templates** > **Microsoft** > **DNS** folder contains the following template:
8+
9+
| Template | Description | TAGS |
10+
| ------------------ | -------------------------- | ---- |
11+
| DNS Record Changes | No customizations required | None |
12+
13+
## LSASS Protection {#lsass}
14+
15+
The **Templates** > **Microsoft** > **LSASS** folder contains the following templates:
16+
17+
| Template | Description | TAGS |
18+
| ------------------------ | ------------------------------------------------------------------------------------------- | ---- |
19+
| LSASS Guardian - Monitor | No customizations required. Detects attempts by other processes to alter the LSASS process | None |
20+
| LSASS Guardian - Protect | No customizations required. Prevents attempts by other processes to alter the LSASS process | None |

docs/threatprevention/7.4/threatprevention/admin/templates/folder/microsoft/dns.md

Lines changed: 0 additions & 8 deletions
This file was deleted.

docs/threatprevention/7.4/threatprevention/admin/templates/folder/microsoft/lsass.md

Lines changed: 0 additions & 9 deletions
This file was deleted.

docs/threatprevention/7.4/threatprevention/admin/templates/folder/privilegeescalation.md

Lines changed: 0 additions & 10 deletions
This file was deleted.

docs/threatprevention/7.4/threatprevention/admin/templates/folder/ransomware.md

Lines changed: 0 additions & 8 deletions
This file was deleted.

0 commit comments

Comments
 (0)