Share via

To get alert when a server is affected by external threat

Aswin Thomas(UST,IN) 426 Reputation points
2023-04-19T08:45:00.0866667+00:00

Hi Team, Greetings...! Our customer needs to be alerted when SCCM server is hit by an external threat. Whether there are any Management packs associated for it. It would be of great help, if this case can be solved. Seeking your help in this case. Thanks in advance, Regards, Aswin Thomas

System Center Operations Manager
System Center Operations Manager

A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.

0 comments No comments

Answer accepted by question author

SChalakov 10,781 Reputation points MVP Volunteer Moderator
2023-04-21T20:26:39.8533333+00:00

Hi Aswin Thomas(UST,IN), I fully agree with Andrew about SCOM being an operational tool in nature. The only MP for SCOM that is security related is the one Andrew mentioned. It has been devolped by Nathan Gau, who is Senior Cyber Security Consultant with Microsoft and was previosly a SCOM PFE. This the download link: Nathangau/SecurityMonitoring @ GitHub It covers a variaty of common security related use cases/vulnerabilities. I have summed those up and included all the links to the details:  

In addition to this I would recommend you to install the new MECM Management Pack (if you haven't done it already), developed by Kevin Holman, as the old one is not supported anymore. Here is the link with some more interesting details: Monitoring Microsoft Endpoint Configuration Manager (MECM)

Some important additional information on the same topic: SCOM Security – the best tips, tools and MPs to secure your SCOM environment This is a session by Nathan Gau, who is the author of the Security MP. Some session info:

With cyber-attacks on the rise, security is top of the agenda for most IT teams. But there is no need to shell out for costly security products when SCOM has the building blocks to do security monitoring and is great for analysing log data. Join Cookdown’s Director of Products, Bruce Cullen, and Nathan Gau, Senior Cyber Security Consultant at Microsoft, for this month’s Coffee Break episode where they will be discussing how SCOM can help with intrusion detection, highlighting known vulnerabilities and augmenting organizational best practices surrounding security. They will also be showing off the latest version of Nathan Gau’s Security Monitoring MP, built from customer requests to use SCOM to do exactly these things. In this webinar, you will learn how:

  • SCOM can be used as a security monitoring tool with the Security Monitoring MP
  • To detect legacy protocols
  • To identify security vulnerabilities before attackers do
  • To look for signs that your IT estate is under attack
  • To help implement Security best practices and processes through SCOM

Last, but not least, another session by Nathan Gau on the same topic, again on SCOMathon: SCOM as a security tool and securing SCOM Session summary:

Nathan’s session covered basic cyber security concepts for the IT professional, as well as how SCOM can be used as a cyber security tool. He also showed how to secure SCOM given that it is a very powerful tool that, if compromised, could easily be exploited by people with bad intentions.


(If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)
Regards
Stoyan Chalakov

Was this answer helpful?

0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Andrew Blumhardt 10,071 Reputation points Microsoft Employee
    2023-04-19T13:47:49.2933333+00:00

    SCOM monitoring is usually operational in nature. You can do some security monitoring but it never really went in that direction (one example provided below). External threats are a broad topic. I am not aware of an on-prem security posture/attack monitoring solution from Microsoft. There are several cloud-based solutions like Defender for Cloud (Defender for Servers), Defender for Endpoint, and Defender for Identity that could help to protect an on-prem SCCM server. https://nathangau.wordpress.com/2017/05/01/introducing-the-security-monitoring-management-pack-for-scom/

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.