Navigation
  • SEARCH HERE
  • SOLUTIONS
    • Information Security Solutions
      • Enterprise Application Security Solutions in Asia
      • Network & Infrastructure Security Solutions
      • Zero Trust Security
      • Security Information and Event Management
      • Remote Monitoring & Management (RMM)
      • File Integrity Management
      • Systems Administration Tools
      • Data Loss Prevention
      • Data / Password Recovery
      • IT Management Solution Offering | Distributor in Asia
      • Identity and Access Management Solution Offering | Distributor in Asia
      • Employee Activity Monitoring (EAM)
      • Digital Forensic Investigation
    • Software Development Solutions
      • Integrated Development Environments
      • Development Components
        • UI Tools
        • Networking Components
        • Office Components
        • Barcode Components
        • Communication Components
      • Imaging Solutions
      • Software Localization
      • Release Automation & Management
      • eLearning Authoring Solutions
      • Charting Solutions
      • PDF Solutions
      • Reporting Solutions
      • Testing & QA
      • Text Retrieval / Enterprise Search
      • Database
  • Services
    • Live Solution Walkthroughs
    • Implementation Services
    • Best Practices Consulting
    • Pre-Sales and Post-Sales Services
  • What's New
    • Our Event
    • Our Blogs
    • Special Offers
  • About
    • About LOGON Software Asia
    • Our Partnership
  • Publishers - Join our network
  • Resellers - Expand your portfolio
  • Procurement Managers
Site logo
  • Solutions
    • Information Security Solutions
      • Identity and Access Management
        • Privileged Access Management (PAM)
        • Multi-Factor Authentication (MFA)
        • Identification Verification (IV)
        • Self-Service Password Reset (SSPR)
      • Network & Infrastructure Security
        • DDoS Mitigation and Protection
        • Digital Forensic Investigation
        • Malware Detection & Analysis
        • Network Monitoring Software
        • Email Security
        • Log Monitoring
      • Endpoint & Device Security
        • Patch Management
        • Remote Monitoring & Management (RMM)
        • Employee Activity Monitoring (EAM)
        • Mobile Device Management (MDM)
      • IT Management
        • IT Service Management
        • IT Asset Management
        • Software Asset Management
        • Hardware Asset Management
        • Software License Management
        • Systems Administration Tools
      • Application Security
        • Development Security | Shift Left AppSec | SAST, SCA, IAST
        • Runtime Protection Solutions | DAST, RASP, WAF, Container Security
        • Strategic Management Solutions | ASPM, MAST, VAPT
      • Data Security
        • Data / Password Recovery
        • File Integrity Management
        • Data Loss Prevention
      • Cloud Security
        • Cloud Security Posture Management
        • Cloud Work Protection
      • External Attack Surface Management
        • Cyber Threat Intelligence
        • Third Party Risk Management
      • Security Operations & Incident Management
        • Security Information and Event Management
        • Security Orchestration, Automation and Response (SOAR)
      • Zero Trust Security
    • Software Development Solutions
      • Integrated Development Environments
      • Imaging Solutions
      • UI Tools
      • Charting Solutions
      • Developer Tools
      • Database
      • Networking Components
      • Office Components
      • Barcode Components
      • Release Automation & Management
      • Software Localization
      • Communication Components
      • Automated Testing
      • eLearning Authoring Solutions
      • Reporting Solutions
      • Text Retrieval / Enterprise Search
      • Testing & QA
  • Services
        • Live Walkthrough Sessions

          Experience the full feature of our key solutions through live platform

          View All Sessions >
        • Implementation Services
        • Pre-Sales and Post-Sales Services
        • Best Practices Consulting
  • Partners
    • Our Partners
    • Partner with LOGON Today!
      • Vendors - Join Our Network
      • Resellers - Expand Your Portfolio
      • Procurement Managers
  • Resources
        • ABOUT US

        • About Us
        • Our Locations
        • Careers@LOGON - We are hiring !
        • DISCOVER

        • Our BlogsNEW BLOGS
        • Our EventsJOIN UPCOMING EVENTS
        • LOGON to CyberSecurity PodcastNEW EPISODES
        • GET HELP

        • Contact Us
        • Help Desk
        • Request a Demo
        • Request a Quote
        • COMPLIANCE

        • 🇭🇰 Hong Kong PDPO
        • 🇮🇳 India DPDP Act
        • 🇸🇬 Singapore PDPA
        • 🇹🇭 Thailand PDPA
  • More results...

View large
Blog, FileAudit, ISDecision Blog

How to See Who Last Accessed or Last Modified your Windows Files | FileAudit

How to See Who Last Accessed or Last Modified your Windows Files

This article was originally published by LOGON’s partner IS Decisions. Click here to view the original article.

As an important security and compliance measure, watch how you can easily identify activity on your most sensitive shared files and folders. With FileAudit you can see who last accessed or modified your Windows files. It not only gives you optimal visibility into what is happening to your organization’s data but the opportunity to react quickly to events.

Video Transcription:

In this video, I’m going to show you how FileAudit can help you to actively monitor accesses on your shared files and folders.

 

Audit Configuration

Here in the console of the FileAudit software, the first thing you do is go to audit configuration and select the most sensitive files and folders on your network that you wish to monitor. From there I can go directly into the ‘File Access Viewer’ to see in real time, the accesses that are happening on the shares that I’ve selected.

 

Find Files Last Accessed / Modified

So, I can see the date and time, the file or folder that was accessed or modified, the access type, whether or not it was denied or granted, the user who attempted to access/modify the file, the machine from where the access was made with its client IP address and the server where the file is stored.

Last Accessed / Modified Windows File

 

Denied Access Activity

I can see easily from here that there are some denied accesses on ‘Accounting and Peopleops’ – some very sensitive folders that contain internal and client data. I can now go ahead and take a closer look at this folder to see who has been accessing it.

Here I can see quickly again that these accesses are denied and they’re by the same user Alice. I can also see that Alice has tried to access these files on separate occasions from different machines.

Because of that, I’m now going to take a closer look at Alice’s overall activity by clicking on her username to bring up a dashboard of all the activity from this user, from the last few days and weeks.

I can see there’s quite a lot of red flags here, once again some denied accesses on sensitive files such as ‘Accounting and Peopleops’. I can scroll down further and see all these accesses from all these files and folders that were read at the same time on the same day. I can see that they happened simultaneously so that can lead me to believe that Alice is selecting a large number of files and copying them to an external drive or possibly to a desktop.

Now that I’ve got this drilled down view of Alice’s accesses I’m going to go ahead and export it into a PDF in case I want to send it to a manager, or in case any other alerts come up with this same user. I’m just going to save Alice’s report as a PDF.

 

Set Alerts on Suspicious Behavior

The next step that I want to put in place is some proactive alerts in case these kinds of accesses happen again. I go back to the main menu and I’m going to access the alert tab. From here I can create my alerts.

The first thing I can do is create a single access alert for any more ‘denied accesses’ on those sensitive folders that we saw – ‘Accounting and Peopleops’. I’m going to give the alert a name “Denied access Alice”. I’m going to select the access status here “denied”, I’ll leave all the access types and I’ll just enter the user Alice. The next thing I’m going to do is select those two paths that we saw earlier ‘Accounting and Peopleopps’. I’ll add the first one Accounting and then I’m gonna add the second one. Just like that and validate that. I don’t want to exclude any hours from this alert, I want to be alerted 24 hours a day. The next thing is to add the recipient for the email, the admin, and I’m also going to add a slack channel where all my admins receive messages so they can see those as well. So now I’ve got that I’m going to save that alert.

The second alert I’m going to set up is going to be a mass access alert for Alice and this is due to the activity we saw on several files or folders being accessed at the same time showing that she could be copying or moving large amounts of data somewhere else.

mass access alert suspicious file activity

I’m going to call this “Mass access Alice”.  I’ll leave the access status and types, I’m just going to add here again our user Alice and I’m going to set a threshold – a fairly low threshold. I’m going to say if there’s 25 files or folders that are accessed within the span of 30 seconds I’d like this alert to be triggered. For the monitor paths I can put everything that’s being audited because, as we saw earlier, these were still accesses that were on files that Alice is allowed to access. Again I’m not going to exclude any hours but I will add the email recipients – the same ones as before – the admin email and my slack channel that receives all these alerts. So I validate that, I’ve saved that alert and now I’ve got my two alerts setup.

So that’s how you can use FileAudit to see file accesses on your files or folders, generate reports and set up alerts to be proactive when suspicious behavior is happening on your network.

File Auditing for Windows Server & Cloud Storage

Proactively track, audit, report, alert on and respond to, all access to files and folders on Windows servers and in the cloud.

Solution Highlight

Get started with FileAudit

Start a free trial with FileAudit, with 30-day full version, no user limit, and free technical support.

Start Your Free Trial
Contact Us Today

FOLLOW US ON

  • LinkedIn
  • Facebook
  • Instagram
  • Twitter
  • YouTube
Read Next:
Application Security BlogArtificial IntelligenceBlogLOGON Blog
AI-Augmented Penetration Testing: Meeting the Scale Challenge
Application Security BlogArtificial IntelligenceBlogIT Management BlogLOGON Blog
The First Autonomous AI Cyber Attack is Here: Is Your Enterprise Ready?
Application Security BlogBlogLOGON Blog
Shift Left, Verify Right: The Blueprint for Modern Application Security Across Asia

Privacy Policy Company Overview

COMPANY

Our Location Career with LOGON Our Partners

SERVICES

Training Services Implementation Services Pre-Sales and Post-Sales Services Best Practices Consulting

GET IN TOUCH

Phone:
Hong Kong: +852 2512 8491
India: +91 70220 22744 / +91 63668 26133
Email: [email protected] ©2025 LOGON International Ltd. All rights reserved
logon logo WHITE

Search engine

Use this form to find things you need on this site

More results...

Fill in the form below
  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Watch On-demand Webinar

  • This field is for validation purposes and should be left unchanged.

Get Your Free UserLock Trial

  • This field is for validation purposes and should be left unchanged.

Download Your Free Trial 10-Day Trial Today

  • Downloading and evaluating Smart Package Studio is quick and easy
  • Includes a short introductory guide that suggests smart features to try
  • Access the full functionality of Smart Package Studio during the trial
  • This field is for validation purposes and should be left unchanged.

Request for Priority Support with our support team

  • This field is for validation purposes and should be left unchanged.
  • Drop files here or
    Max. file size: 30 MB.

    Get Free Assessment of your Web Asset

    Request a free non-intrusive security assessment of your website. Get a report with an overview of client-side security risks.

    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form

    Recommend a Topic

    • This field is for validation purposes and should be left unchanged.

    Partner with Us on the next episode

    • This field is for validation purposes and should be left unchanged.

    Watch On-demand Webinar

    • This field is for validation purposes and should be left unchanged.
    Start PreCrime Network for Free

    Oops! We could not locate your form.

    Book a Free Demo Today

    Get Your Free Trial

    Oops! We could not locate your form.

    Get Your Free Trial
    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form
    • This field is hidden when viewing the form
    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form