User Activity Monitoring for the Proactive Enterprise

  • USER ACTIVITY MONITORING

Overview

Focused user activity monitoring increases scrutiny when risk indicators warrant it, including access to highly confidential or classified assets. DTEX Focused Observation targets specific devices, applications, user rules, or persons of interest, reducing operational overhead while giving teams actionable insight into potential insider threats. 

Patented DMAP+ technology correlates contextual intelligence across data, machines, applications, and people. It identifies reconnaissance, circumvention, aggregation, and obfuscation before data exfiltration occurs. DTEX also maintains a continuous audit trail of endpoint metadata on and off the organizational network. When a user is elevated for focused observation, teams can capture browser activity through TLS inspection, video, screens, and keystrokes, then use playback, frame-by-frame review, export, and archival workflows. 

What You'll Learn

  • How to increase monitoring for specific devices, applications, user rules, or persons of interest.
  • How alert stacking, machine learning, and automated activity correlation reduce false positives and analyst overhead.
  • How file lineage and configurable MD5, SHA1, and SHA256 hashing track files after their names or locations change.
  • How user risk scores profile correlated behavior and label it as malicious, negligent, or compromised.

Frequently Asked Questions

What is focused user activity monitoring?

Focused user activity monitoring increases scrutiny when risk indicators warrant it, such as access to highly confidential or classified assets. DTEX Focused Observation can target specific devices, applications, user rules, or persons of interest.

What does DTEX user activity monitoring software include?

DTEX maintains a continuous audit trail of endpoint metadata on and off the organizational network. For users elevated to focused observation, teams can capture browser activity through TLS inspection, video, screens, and keystrokes. Available workflows include playback, frame-by-frame review, export, and archival.

What are the benefits of focused user activity monitoring?

Focused monitoring reduces operational overhead while providing actionable insight into potential insider threats. Alert stacking, machine learning, and automated activity correlation help reduce false positives and analyst workload.

How does DTEX identify insider risk before data exfiltration?

DTEX uses patented DMAP+ technology to correlate contextual intelligence across data, machines, applications, and people. It identifies early indicators of intent, including reconnaissance, circumvention, aggregation, and obfuscation.

How does file lineage support file integrity monitoring?

File lineage tracks files after their names or locations change. DTEX uses configurable MD5, SHA1, and SHA256 hashing to support this tracking. 

How do user risk scores support end user monitoring?

User risk scores profile behavior across correlated activities. DTEX labels the behavior as malicious, negligent, or compromised. 

Ready to Learn More?