File Integrity Monitoring Overview

Welcome to

File Integrity Monitoring (FIM) Help

With Qualys FIM, you can easily see all important changes happening across your files, folders, registry settings, access events, and even network device configurations in one place. You get real-time alerts and detailed reports that help you quickly spot unauthorized changes, strengthen your security, and stay compliant.

What is FIM

In today’s dynamic cybersecurity landscape, IT environments span diverse systems and clouds, making the integrity of configuration files, system binaries, and registry settings essential for security and stability. Any unauthorized or unintended change whether from attackers, malware, or internal errors can undermine security controls, introduce compliance risks, and disrupt operations.

Qualys File Integrity Monitoring (FIM) is a cloud-based security solution that detects and reports changes in files, directories, and registry settings across IT environments. It helps organizations ensure security, maintain compliance, and streamline auditing by identifying unauthorized or suspicious modifications that could indicate security breaches.

File Integrity Monitoring (FIM) provides the visibility and governance necessary to maintain a secure and compliant IT ecosystem.

Key Features of FIM

Real-time Monitoring

⟳

FIM detects unauthorized or suspicious changes to critical system files, helping to reduce the time to respond to potential breaches.

Learn More β†’

Centralized Management

⟳

FIM is a cloud-based solution, offering centralized visibility and management of file change events.

Learn More β†’

Alerting

⟳

FIM automatically alerts you when it detects unauthorized or suspicious changes.

Learn More β†’

Reporting

⟳

FIM generates reports to capture events and incidents occurring in your files.

Learn More β†’

User Impersonation Detection

⟳

FIM can identify and alert if someone is impersonating a privileged user to gain unauthorized access.

Learn More β†’

File Access Monitoring (FAM)

⟳

FIM can capture file access attempts, providing detailed information about who, what, when, and where access attempts occur.

Learn More β†’

Compliance Support

⟳

FIM helps organizations meet compliance requirements like PCI DSS, HIPAA, GDPR, and others.

Learn More β†’

Agentless Network Monitoring

⟳

FIM can monitor network devices for configuration changes, even without requiring agents to be on the devices.

Learn More β†’

FIM Integration with CAR

⟳

You can perform the database monitoring by configuring FIM with the help of Qualys CAR subscription

Learn More β†’

FIM JourneyΒ 

Follow the FIM Journey to understand how automated assessments and seamless script execution work.

Create Profile

Create your profile for Windows or Linux

Activate Profile

Activate your profile upon profile creation

Configure Rules and Execute them

Configure rules and patterns for your profile and execute them

View Events

Receive complete information in FIM events detected by different sources

Get Reports

Download the reports in required format

Monitor Status

Monitor status in FIM

How Do I Get Started with FIM

Prerequisites

Before using FIM, ensure the Cloud Agent application is enabled for your subscription and the required Qualys Cloud Agent is installed and activated for your assets.

Learn More β†’

Role-based Access Control (RBAC)

Ensure user roles are properly defined, as FIM uses RBAC permissions to control specific script operations.

Learn More β†’

Tag based User Scoping

Tag-based User Scoping ensures Sub-users can access only those assets and related FIM data that match their assigned tags, while untagged assets remain accessible to all Sub-users.

Learn More β†’

FIM APIs

Get started with FIM APIs to automate the APIs like event, incidents, alerting, correlation, profile and assets.

Learn More β†’

Looking for something else?

Get the most out of your Qualys FIM with these helpful resources.

Training Videos KnowledgeBase Articles Blogs Support Product Tours

Let's Get Started