See who has access, and how they use it
The User Auditor tracks accounts across Active Directory and Linux servers in one view. Identity detections alert you to suspicious account activity in Windows domains and Microsoft 365.
Active Directory and Linux
One view of accounts from Windows domains and Linux servers.
Stale and inactive accounts
Find disabled, deleted, stale and service accounts, and see which accounts were active in the last 24 hours.
Alerts on risky activity
Detections flag suspicious account activity, such as changes to privileged groups or brute-force sign-in attempts.
Identity attack detection
Built-in rules detect Golden and Silver Ticket attacks, Kerberoasting, AS-REP roasting and attempts to copy the Active Directory database.
Cloud identities
Microsoft 365 rules catch suspicious guest invitations, conditional access bypass and brute-force attempts.
Questions buyers ask
Which identity sources are supported?
Active Directory domains through the Windows agent, Linux servers through the Linux agent, and cloud identities through the Microsoft 365, Azure, AWS and Google Cloud integrations.
Can I find inactive accounts?
Yes. The User Auditor lists stale, disabled and deleted accounts and shows when each account was last seen. That makes regular access reviews and compliance checks faster.
Does it detect attacks or only report on accounts?
Both. Account data is kept for audits, and identity detection rules raise alerts in real time. An alert can trigger an automated response, such as disabling the affected user.
Related capabilities
- Threat detection600+ detection rules mapped to MITRE ATT&CK run on every event in real time. Tag false positives, mute noisy rules and see who is attacking whom.
- ComplianceScore 9 frameworks, including HIPAA, PCI DSS 4.0, SOC 2, ISO 27001 and CMMC 2.0, from live events, and download PDF reports for auditors.
- Automated responseBuild response flows on a visual canvas to isolate hosts, kill processes, log off and block users or IPs. Track every run and use a live console.
- Dark web monitoringMonitor the dark web for leaked staff credentials and company data, using InsecureWeb's 19 billion+ records, and act before attackers log in.
Protect your organization this week, not next quarter
Talk to an engineer today, or start using UTMStack in minutes.
Need to extend your SOC team?
Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.
Want to try UTMStack?
Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.