Information
File Integrity Monitoring (FIM) is a feature that monitors critical system files in Windows or Linux for potential signs of attack or compromise.
Rationale:
FIM provides a detection mechanism for compromised files. When FIM is enabled, critical system files are monitored for changes that might indicate a threat actor is attempting to modify system files for lateral compromise within a host operating system.
Impact:
File Integrity Monitoring requires licensing and is included in these plans:
Defender for Servers plan 2
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Audit from Azure Portal
From the Azure Portal Home page, select Microsoft Defender for Cloud
Under Management select Environment Settings
Select a subscription
Under Settings > Defender Plans, click Settings & monitoring
Under the Component column, locate the row for File Integrity Monitoring
Select On
Click Continue in the top left
Repeat the above for any additional subscriptions.
Default Value:
By default, File Integrity Monitoring is Off.