Currently we monitor some systems with the filesystem change. Almost all the time, any triggers to this are from our updates pushed by the SCCM server. I'd like to start monitoring the systems for when patches are applied by SCCM and correlate that with the filesystem changes via some searches to quickly rule these out as malicious behavior.
How can I monitor SCCM applying updates?
We're hosting a contest for the best SCCM app.
Microsoft SCCM - The first place winner in the Microsoft SCCM app category wins $30,000 and a complimentary pass to .conf 2015 - Splunk's premier annual user conference. Value: approx. $1,695.
Innovation - The first place winner in the Innovation category wins $20,000 and a complimentary pass to .conf 2015 - Splunk's premier annual user conference.