A file dropped on a municipal server overnight. A new startup entry in the Windows registry. A permission widened on a configuration file. None of these leaves a Windows event unless someone set up auditing for that exact file or key beforehand, and that setup process is manual and easy to get wrong.
Version 1.1.0 of the Guardsix Log Collection Agent gives you a second, independent way to see these changes. It adds file integrity monitoring and Windows registry monitoring to the agent you already run, building on the original feature launch in July 2026. Version 1.1.0 is available today in priority access, with general availability planned for late October.
What is new in version 1.1.0
- See when important files and registry keys are created, changed, deleted, renamed or have their permissions edited.
- Get one clear event per change in Guardsix SIEM, with the before and after values.
- Monitor independently of Windows audit policy, set up in the agent policy you already use.
- Start with ready-made integrity and agent health dashboards, plus an agent health alert.
- Benefit from security, hardening and reliability improvements in the same upgrade.
All of it runs inside the agent you already deploy, with no new licence to buy.
Review the changes Windows does not log on its own
A municipal IT team of four is preparing for an audit. Windows retains what it is told to record, object by object. To show that a configuration file or a registry key has not changed, the team would need to switch on auditing for each one, on every server, and keep it correct as systems change. In practice, most teams cover the obvious files first and leave the rest.
The gap shows up later. An auditor asks what changed and there is no event to show. Alternately, a foothold might have sat in the registry for weeks. Picture a hospital server whose service program changes overnight and nobody knows until a clinician reports it on the morning shift. For the leader accountable for the estate, that is an evidence gap that demands immediate accountability.
Run file and registry monitoring in Guardsix SIEM
Name the folders, files and registry keys that matter. The agent checks them on the schedule you set and sends one event for every change it finds. A utilities team running Windows servers beside operational systems can now learn that a configuration file changed on the next scan, and see exactly what it changed from and to.
Upgrade the agent, then list the files and registry keys that matter most in the policy you already use. Once the first scan has built its baseline, every change it finds on your Windows endpoints and servers arrives in Guardsix SIEM as one event you can search and build alert rules on.
How it works
- Choose. List folders, files and registry keys in the YAML policy the agent already reads. The policy is validated up front, so mistakes surface before the agent runs.
- Scan. The agent scans on the interval you set. Content hashing is optional, with MD5, SHA-1 or SHA-256 available.
- Compare. Each scan is compared against a baseline the agent keeps locally. The baseline builds itself on first run and compacts over time, so it does not keep growing.
- Send. The agent sends one change event per change to the Guardsix SIEM you already use.
These details matters for a small team. Up-front validation means a typo in a path does not turn into a silent gap across the estate. The self-building, self-compacting baseline means nobody maintains a reference set by hand. On hashing, SHA-256 costs more computation and is less prone to collision, MD5 is the opposite and SHA-1 sits between, so you can match the choice to the host.
One clear event for every change
Each change becomes one normalised event, with before and after values, in one of five types.
| Change type | What it means |
|---|---|
| Create | A new file, key or value appears |
| Modify | Content or a value changes, with an optional old and new hash for files |
| Delete | An object is removed |
| Rename | A file is renamed |
| Permission change | An access control list (ACL) or system access control list (SACL) is edited |
Here is an illustrative example of a changed startup entry:
| Action | Host | Path | Before | After |
|---|---|---|---|---|
| Modify | finance-srv-02 | HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SyncHelper | C:\Program Files\Vendor\sync.exe | C:\Users\Public\sync.exe |
Because each change arrives as a single normalised event, you search, alert and report on it in the SIEM like any other log.
What this looks like in a real campaign
Operation Neusploit was an APT28 campaign that exploited a Microsoft Office flaw (CVE-2026-21509). The attackers maintained access through quiet registry edits: a hijacked COM entry that loaded their DLL, a Run key that started the loader at logon in some samples, and Outlook macro settings lowered so a malicious project could load.
The same campaign dropped a loader DLL into a ProgramData folder. Add those keys and folders to the agent's policy and it finds each change on the next scan, sending one event with the before and after values to Guardsix SIEM, even where nobody had set up auditing for them.
| log_ts | host_name | agent_id | path | action | resource_type | count |
|---|
Illustrative example. Host names, agent identifiers and paths are sample values. Each change appears at the next scheduled scan and arrives as a single event. Hover a ribbon or select a row to trace one change.
Working alongside native Windows auditing
Native Windows auditing still has a place, and we recommend keeping it wherever you have it. The log collection agent adds a second view that does not depend on Windows.
| Native Windows auditing alone | With the agent's file and registry monitoring |
|---|---|
| Set up by hand, object by object | Watches the paths and keys you list directly |
| Adds volume to the Windows Security log | Sends its own purpose-built event with before and after values |
| Gives a point-in-time event stream | Keeps a baseline, so state can be compared over time |
| Goes quiet once someone edits a file's SACL | Flags every ACL and SACL edit, so audit tampering is itself an event |
Log collection built for the way lean teams operate
File and registry monitoring arrives inside the agent you already run, so there is no new licence, no new server and no new install. Since Guardsix prices on nodes instead of how much data you ingest, monitoring events across your estate does not change what you pay. For a lean team, that keeps spend predictable and makes decision-making simple.
What to do now
- If you already run the agent: Reach out to your Guardsix contact to upgrade to version 1.1.0, then add the files and keys that matter most.
- If you stayed on the legacy Logpoint agent for file or registry monitoring: that requirement is now covered. Talk to your Guardsix partner about migration.
- If you are new to the agent: ask your Guardsix partner for a demo of file and registry monitoring, or read the documentation and watch the walkthrough in Guardsix Academy.