Security Monitoring Policy

Ensure airtight security across Windows, macOS, and Linux systems with this plug-and-play monitoring policy. Detect and remediate DNS, firewall, admin user, sudo user, and SSH key anomalies in real-time—no coding required.

Problem overview.

The challenge this resource is designed to solve.

Maintaining consistent security across diverse operating systems can be a daunting challenge for IT professionals. Vulnerabilities such as disabled firewalls, unauthorized admin accounts, failed admin login attempts, or misconfigured DNS settings can leave systems exposed to attacks. This resource provides a holistic solution to monitor and secure your entire infrastructure—Windows, macOS, and Linux—through a unified policy.

About this resource.

What it does and how it fits into your workflow.

This cross-platform monitoring policy offers a centralized solution for detecting security vulnerabilities across Windows, macOS, and Linux systems in real-time. It ensures comprehensive oversight by monitoring critical parameters such as DNS configurations, firewall status, failed admin login attempts, and administrative user accounts on Windows; user accounts, firewall status, DNS settings, and failed admin logins on macOS; and sudo user access, SSH keys, DNS settings, failed admin logins, and firewall status on Linux. By addressing these core security components, the policy provides IT professionals with the tools needed to maintain a secure and stable infrastructure.

Designed to be effective for both workstations and servers, this policy is pre-configured and ready for immediate implementation without requiring any scripting expertise. It proactively identifies potential security concerns, including patterns of failed admin login attempts, empowering IT teams to take swift corrective action. Additionally, it can be seamlessly paired with automations to remediate issues automatically, further streamlining the process and reducing the risk of human error.

Included monitors: 22 checks
Monitor nameMonitor type
Linux SSH Keys (Script monitor)Linux SSH Keys (Script monitor)
macOS Firewall (Script monitor)macOS Firewall (Script monitor)
Windows Firewall (Script monitor)Windows Firewall (Script monitor)
Windows DNS (Script monitor)Windows DNS (Script monitor)
macOS DNS (Script monitor)macOS DNS (Script monitor)
Linux DNS (Script monitor)Linux DNS (Script monitor)
Linux Firewall (Script monitor)Linux Firewall (Script monitor)
Account Lockout (Event Log monitor)Account Lockout (Event Log monitor)
New Admin User Added (Event Log monitor)New Admin User Added (Event Log monitor)
Event Log Cleared (Event Log monitor)Event Log Cleared (Event Log monitor)
Windows Defender Threat Detection (Event Log monitor)Windows Defender Threat Detection (Event Log monitor)
Unexpected Admin Account (User monitor)Unexpected Admin Account (User monitor)
Excessive Admin Login Failures (Failed Login monitor)Excessive Admin Login Failures (Failed Login monitor)
Antivirus Monitor (Antivirus monitor)Antivirus Monitor (Antivirus monitor)
Remote Access Tool Detected (Application monitor)Remote Access Tool Detected (Application monitor)
Linux Monitor - SSH KeysRun script
macOS Monitor - FirewallRun script
Windows Monitor - FirewallRun script
Windows Monitor - DNS ServersRun script
macOS Monitor - DNS ServersRun script
Linux Monitor - DNS ServersRun script
Linux Monitor - FirewallRun script

Included with this resource.

Everything added when you import.

Scripts

  • Linux Monitor - SSH Keys
  • macOS Monitor - Firewall
  • Windows Monitor - Firewall
  • Windows Monitor - DNS Servers
  • macOS Monitor - DNS Servers
  • Linux Monitor - DNS Servers
  • Linux Monitor - Firewall

Tags

  • WORKSTATION
  • SERVER

Use cases.

Common ways to put this resource to work.

  • IT Teams: Monitor and secure endpoints and servers globally with minimal setup.
  • MSPs: Standardize security practices for clients with varying infrastructure.
  • Incident Response: Quickly detect and act on anomalies, such as unexpected admin accounts or disabled firewalls.
  • Compliance: Ensure firewall and account configurations align with organizational or regulatory standards.

Recommendations.

Practical guidance for a reliable rollout.

  • Testing: Begin with a test group of devices (workstations and servers) before applying globally.
  • Pairing: Combine with automations for auto-remediation, e.g., enabling firewalls or removing rogue admin accounts.
  • Configuration: Customize thresholds and severity levels to align with your organizational policies.
  • Monitoring Tags: Use workstation and server tags to target the appropriate devices.
  • Documentation: Keep a record of changes made by the policy for auditing purposes.

Frequently asked questions.

What happens if a policy flags an issue?

Depending on your configuration, flagged issues can trigger alerts or paired automations to remediate them automatically.

Can I customize the thresholds and settings?

Yes, you can adjust thresholds (e.g., frequency or duration) to suit your infrastructure.

How do I ensure this policy doesn’t conflict with existing configurations?

Apply the policy to a test group first and review alerts to ensure compatibility with your current setup.

Is any scripting required?

No, this resource is fully configured for immediate use—no coding needed.

Can this work with other Level automations?

Absolutely! Pair it with automations to fix issues like enabling firewalls or removing unauthorized users.

Ready when you are.

No credit card. No sales call. Just sign up and start managing.