UTMStack

See who has access, and how they use it

The User Auditor tracks accounts across Active Directory and Linux servers in one view. Identity detections alert you to suspicious account activity in Windows domains and Microsoft 365.

UTMStack · User Auditor
The User Auditor overview with total, active, disabled and deleted accounts, accounts seen in the last 24 hours, a breakdown by domain and the account list.
  • Active Directory and Linux

    One view of accounts from Windows domains and Linux servers.

  • Stale and inactive accounts

    Find disabled, deleted, stale and service accounts, and see which accounts were active in the last 24 hours.

  • Alerts on risky activity

    Detections flag suspicious account activity, such as changes to privileged groups or brute-force sign-in attempts.

  • Identity attack detection

    Built-in rules detect Golden and Silver Ticket attacks, Kerberoasting, AS-REP roasting and attempts to copy the Active Directory database.

  • Cloud identities

    Microsoft 365 rules catch suspicious guest invitations, conditional access bypass and brute-force attempts.

One list of every account

The User Auditor collects accounts from Active Directory and from Linux servers. Filter by Windows or Linux, see totals for each domain, and open any account to check its status and when it was last seen. Disabled users stay marked as disabled across updates.

Audit changes to access

UTMStack reads Windows security events for account creation, deletion, sign-ins, and group membership and permission changes, and keeps them as searchable records. Search any user's activity history in Log Explorer, and use the stale account list for regular access reviews.

Catch identity attacks

Attackers who steal one account usually try to get more. Built-in rules watch for abuse of Kerberos, the Windows domain sign-in system, attempts to copy domain credentials, and abuse of protected admin groups. Microsoft 365 rules extend the same watch to cloud sign-ins.

Questions buyers ask

Which identity sources are supported?

Active Directory domains through the Windows agent, Linux servers through the Linux agent, and cloud identities through the Microsoft 365, Azure, AWS and Google Cloud integrations.

Can I find inactive accounts?

Yes. The User Auditor lists stale, disabled and deleted accounts and shows when each account was last seen. That makes regular access reviews and compliance checks faster.

Does it detect attacks or only report on accounts?

Both. Account data is kept for audits, and identity detection rules raise alerts in real time. An alert can trigger an automated response, such as disabling the affected user.

Protect your organization this week, not next quarter

Talk to an engineer today, or start using UTMStack in minutes.

Need to extend your SOC team?

Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.

Want to try UTMStack?

Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.