XMP for Microsoft Windows Security
For companies implementing Microsoft Operations Manager (MOM) as their core system for monitoring Windows events and system performance and automating response actions, NetIQ provides an integrated security management solution. XMP for Microsoft Windows Security is one component of NetIQ's XMP Base Pack for MOM that extends native MOM capabilities to support and monitor server hardware, viruses and Windows security.
The Business Problem
In today's business climate, you've got to stay abreast of security issues within your Microsoft Windows environment. Knowing about events and security breaches after they happen is too late. You've got to take preventive action and improve efficiency. Finally, you've got to provide reports to prove value to your manager or director.
The NetIQ Solution
XMP for Microsoft Windows Security extends the MOM architecture and functionality, allowing you to react to security events in real-time to protect critical systems and data.
This module not only responds to breach attempts, but also tracks security incidents from origination through resolution to keep you aware of all security incidents. It also helps you understand your organization's vulnerability to common hacking methods and protects against attempts by detecting log-on violations and unauthorized services.
Key Features and Benefits
- Stops security breaches in their tracks by detecting and automatically terminating unauthorized server account use and applications or rogue processes, such as Back Orifice and Net Bus. This module also detects any monitored resource listening on unauthorized TCP or UDP ports and changes made to sensitive files and directories.
- Bridges the security knowledge gap by extending MOM's knowledge base with packaged Security Knowledge.
- Quickly identifies new alerts and potential threats with more than 30 out-of-the-box security views and predefined reports. With this information, you can clearly display or document critical trends and data.
- Protects your network from unauthorized services, ensuring security by detecting unauthorized services.
- Provides critical information about potential hack attempts. This module detects log-on violations and password cracking attempts and provides this critical information to security groups.
- Lets you get above the noise with event correlation and offers automated notification and response so you can handle complex event data-helping you manage the noise created by the constant flow of security event data.
- Tracks and responds to security incidents from origination through resolution. Customizable rules allow you determine how security incidents are processed.
- Exposes your vulnerability to common hacking methods. XMP for Microsoft Windows Security detects vulnerable resources on your network, administrator loopholes or changes to authorizations that may leave doors open for hackers.


