๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

On-prem file monitoring

Your file server should tell you when something's wrong.

The share that quietly gets mass-encrypted, or the folder an insider shouldn't be browsing, Lavawall® watches file create, change, access, and delete events on your on-premises Windows servers, attributed and timestamped.

Start my free trial, no credit cardSee how it works

Per-server ยท access & change events ยท ransomware-pattern detection

Watch server file monitoringVideo coming soon

On-prem visibility you probably don't have

Access and change, attributed

Creates, writes, deletes, renames, and ACL changes on monitored servers and shares, the audit trail that on-prem file servers rarely provide out of the box. Each record carries the path, the operation, the actor (the SID where the OS exposes it), the source IP for share access, the timestamp, and a hash of the file before and after.

  • Windows: minifilter driver + Security log IDs 4663, 4660, 4670
  • Windows file-share access: events 5140 & 5145 with source IP
  • Linux: auditd & inotify on NFS and Samba shares
  • macOS: Apple Endpoint Security framework (no kernel extensions)
  • Antivirus-tampering: Defender exclusions & AV service changes
  • Persistence paths: System32, Program Files, scheduled tasks, service binaries

Ransomware patterns surface fast

A burst of rapid file changes across a share is the signature of ransomware. Lavawall® flags it, and the Akira Ransomware Hunter hunts the IOCs across your fleet.

Evidence that stands up to an audit

The same file-integrity monitoring maps to controls under SOC 2, HIPAA, NIST SP 800-171, CMMC 2.0, PCI DSS v4, ISO 27001:2022, and CIS Controls v8.

Simple per-server licensing

Add the servers that matter. File access monitoring extends across servers and tenants as you grow.

On-prem file share events and user activity, with actor, path, and operation

Not sure what's on your file shares?

ThreeShield, the CISSP/CISA team behind Lavawall® will review your file-server exposure and access, and lock down what shouldn't be open.

Common questions

What does on-prem file monitoring watch?
File create, change, access, and delete events on monitored Windows servers and shares, attributed and timestamped.
How is it licensed?
Per on-premises server; file access tracking across servers/tenants is included in higher tiers or available a la carte.
Does it help detect ransomware?
Yes, the wide, rapid file-change pattern ransomware creates is exactly what this surfaces, alongside the Akira Ransomware Hunter.

Start my free trial →