Cybersecurity analyst reviewing audit logs and forensic investigation
IT Governance & Audit · On-Premise

Do you really know
who is doing what
with your data?

See who accesses what, when and why. Mitra Auditor gives you the answers you need to identify risks, detect threats and automate compliance. With integrated forensic analysis.
No agents. No complexity. Just control.

Explore technology
Native coverage across your entire infrastructure
Active Directory
Office 365
Azure Entra ID
SQL Server
PostgreSQL
NAS
Windows Logon
Windows Server

The problem organisations ignore until it is too late

Most incidents do not start from outside. They start from within: a valid credential, an excessive permission, an anomalous session or access to a critical file. By the time they are detected, many organisations can no longer reconstruct what happened, who did it and when it started.

74%
of breaches involve the abuse of privileged credentials

A misassigned privilege, an unrevoked access or a compromised credential can open the door to your entire infrastructure. Without audit, the damage is discovered before the cause.

  • 01

    Total opacity in Active Directory

    Changes to groups, policies and permissions with no audit trail. An attacker with valid credentials can escalate privileges without triggering obvious alarms.

  • 02

    File access with no traceability

    Who accessed that contract before the competitor made the same offer? Without file auditing, the answer is usually: nobody knows.

  • 03

    Reconstructing an incident: hours searching scattered logs

    When something happens, the team opens different consoles, exports events and manually cross-references logs. Hours later, they may still not have a reliable sequence of events: actor, origin, actions, affected resources and impact.

  • 04

    Regulatory compliance without evidence

    GDPR, ENS, ISO 27001 and NIS2 require evidence: who accessed what data, when and with what outcome. Without structured records, an external audit becomes a crisis.

What Mitra Auditor answers

The questions your team needs to answer today

No more scattered logs. No more noise. Clear answers for security, compliance and incident investigation.

Active Directory

Who modified that security group and when?

Changes to users, groups, GPOs and permissions recorded with actor, action, origin and precise timestamp.

File Server

Who accessed that confidential folder before the incident?

Accesses, creations, modifications, deletions and permission changes on files. Who, what, from where and when.

Logon Activity

Did that user log in outside office hours from an unknown origin?

Logins, authentication failures, remote accesses and use of explicit credentials detected and traced in real time.

Exchange Online

Did someone create an auto-forwarding rule to an external address?

Audit of inbox rules, mailbox permissions, forwarding and suspicious activity in corporate email.

SQL Server · PostgreSQL

Who ran a bulk UPDATE on a critical table?

Queries, bulk updates, schema changes and privileged accesses recorded with user, origin, affected object and executed statement.

Windows Server / Workstation

When did that new service appear on the production server?

Services, scheduled tasks, local users, installed software and configuration changes under continuous traceability.

Forensic Analysis

What exactly happened from the first anomalous access to the impact?

Automatic event correlation across identity, sessions, files, databases and Microsoft 365 to reconstruct actor, sequence, affected resources and impact.

Microsoft Copilot

What corporate data is the AI processing?

Visibility into Copilot interactions within Microsoft 365 to identify documents, data and conversations exposed to generative AI.

For every security stakeholder

Built for those who need to give answers

Risk visible. Evidence ready.

The CISO needs to know whether the organisation is exposed, not review logs. Mitra Auditor consolidates privileged accesses, critical changes, anomalous activity and forensic evidence in an executive risk view.

  • Risk view by module, severity and origin
  • Alerts on elevated privileges, bulk accesses or out-of-pattern activity
  • Executive reports for GDPR, ENS, ISO 27001 and NIS2
  • Forensic evidence ready for audit, crisis committee or regulatory notification
Executive view Exposure → Evidence
Identity
Files
Microsoft 365
Actor Action Resource Impact
72hEvidence prepared for breach notification.
100%Audit data stays inside the organisation.

Full control without deployment complexity.

The IT Director needs visibility over the infrastructure without adding operational overhead. Mitra Auditor installs centrally, with no agents on production servers, and collects events from native sources.

  • Guided installation and fast go-live
  • No agents on production servers, no incompatibilities after updates
  • Audit policies applied automatically by the system
  • Simultaneous coverage of on-premise infrastructure and Microsoft 365
IT Operations Native sources → Central panel
Active Directory
File Server / NAS
SQL / O365
Source Collector Correlation Panel
<30 minWizard-guided go-live.
12+Audit areas from a single central console.

Evidence ready for audit.

The compliance officer needs to demonstrate, not explain. Mitra Auditor structures the evidence required by GDPR, ENS, ISO 27001 and NIS2: who accessed what data, when, from where, with what outcome and what changes were made.

  • Predefined reports by regulatory framework: GDPR, ENS, ISO 27001 and NIS2
  • Verifiable record of access to personal and confidential data
  • Export to PDF and CSV for external auditors
  • Structured forensic evidence for breach notification
Compliance Event → Evidence → Report
Accesses
Changes
Reports
Event Evidence Report
GDPR · ENSAccesses, activity and breach response.
ISO · NIS2Traceability for controls and continuity.

Incident investigation in minutes, not days.

The security team needs to investigate fast. The Activity Inspector and forensic module reconstruct the chain of an incident by crossing identity, sessions, files, databases and Microsoft 365.

  • Visual Inspector: interactive graph of actor → machine → action relationships
  • Full-text search across all events with dynamic filters
  • Automatic correlation across AD, File Server, Logon, databases and Microsoft 365
  • Real-time alerts by email and Microsoft Teams for critical events
Investigation Alert → Actor → Impact
Logon
Files
Office 365
Alert Actor Path Impact
AlertEmail and Microsoft Teams for critical events.
HistoryAvailable from day one. Configurable retention.

Total coverage across every layer of your infrastructure

Twelve specialised audit modules. A single control panel. Complete visibility.

Active Directory

Active Directory

Audit of users, groups, GPOs, computers and permissions. Every directory change recorded with who, what, when and from where.

Identity & Access
Windows Logon Activity

Windows Logon Activity

Full record of logins and logouts, failed authentications, use of explicit credentials and Kerberos tickets across all domain computers.

Authentication
Windows File Server

Windows File Server

Creation, modification, deletion, renaming and permission changes on files and folders. Who accessed, what they did and from which computer.

Data & Files
Windows Server

Windows Server / Workstation

Installed or modified services, local users, local groups, scheduled tasks, start and shutdown events. Full system state control.

Infrastructure
SQL Server

SQL Server

Read, write and schema modification operations on SQL Server databases. Audit of privileged accesses and configuration changes.

Databases
PostgreSQL

PostgreSQL

Native audit via pgAudit. DDL, DML and access statement logging with actor, object and outcome resolution for PostgreSQL environments.

Databases
NAS Syslog

NAS Syslog

Syslog event reception and analysis from Synology and QNAP NAS devices. File accesses, creations, deletions and moves on network storage.

NAS Storage
Behaviour Analytics

User Activity Analysis

Dynamic learning and visibility into the user's real behaviour at the workstation. Detection of anomalous patterns, out-of-hours activity and deviations from normal behaviour.

Behaviour
Exchange Online

Exchange Online

Mailbox accesses, sends, deletions, permission changes and inbox rules. Full audit of corporate email in the cloud.

Email
SharePoint Online

SharePoint Online

Accesses, downloads, sharing and permission changes on SharePoint documents. Visibility into who accesses what corporate information in the cloud.

Documents
Microsoft Teams

Microsoft Teams

Channel and team creation and deletion, sensitive messages, file sharing and configuration changes. Corporate collaboration audit.

Collaboration
Microsoft Copilot

Microsoft Copilot

Log of Copilot AI interactions in the Microsoft 365 environment. Visibility into what corporate information is queried, processed or exposed to AI.

AI & Productivity
Power Platform

Power Platform / Power Automate

Audit of flows created, modified or deleted in Power Automate. Control over process automation that may access or move sensitive data.

Automation
Azure Entra ID

Azure Entra ID

Authentication events, role changes, licence assignments and administration activity in Azure Active Directory. Cloud identity under control.

Cloud Identity
Differential technology

Beyond event logging

Most solutions on the market simply collect logs. Mitra Auditor turns them into actionable intelligence.

UBA · User Behavior Analytics

User Behaviour Analytics

Mitra Auditor learns how each user works: usual hours, devices, file volumes, paths, applications, email, SharePoint and desktop activity.

When someone deviates from their pattern — out-of-hours activity, access to folders never visited before, simultaneous sessions or anomalous operation volume — it generates an anomaly with a risk score and links it to other indicators to detect patterns such as exfiltration preparation, credential abuse or lateral movement.

John SmithLearned usual profile
Risk score86
Out of hours1
New paths3
Anomalous operations12x
File volume
Access to new paths
Alert priority
Deviation detectedElevated riskPriority alert
Pattern detected: exfiltration preparation.

Activity Inspector

Interactive visualisation of all audited activity. Connect actors, machines and actions in a single graph view. Identify patterns, lateral movement and anomalous behaviour at a glance.

Forensic Analysis

Deterministic correlation engine that reconstructs the exact sequence of an incident: actor, origin, actions taken, affected resources and impact.

Real-Time Alerts

Configurable rules by module, action type, user, device or time range. Immediate notifications when something that should not happen does.

Compliance Reporting

Predefined reports for GDPR, ENS, ISO 27001 and NIS2, with filters by period, user, source and action type. Export to PDF and CSV.

Mitra Data Security Suite

Three products. One integrated platform.

Each Mitra solution works independently. Together, they form the most complete security platform on the market for Windows and Microsoft 365 environments.

IT Governance & Audit

The suite's central panel. It consolidates activity across the entire infrastructure and, when combined with the other Mitra products, incorporates their security logs into the same audit panel.

Native integration
Data Security

When Mitra Antiransomware detects an attack, Mitra Auditor automatically incorporates those events: affected files, patient zero, encryption timeline and response taken.

Learn about Mitra Antiransomware →
Native integration
Identity Governance

Mitra Password events — password resets, MFA enrolments, lockouts and credential changes — appear directly in the audit panel for correlation with the rest of the activity.

Learn about Mitra Password →

Integration between products is optional. Each Mitra solution can be purchased and deployed completely independently.

Differential architecture

Maximum visibility.
Zero deployment complexity.

Mitra Auditor does not install permanent agents on monitored servers. It remotely accesses native logs, APIs, databases and Microsoft 365 services from a centralised installation.

  • No additional software on your production servers
  • No risk of blue screens or incompatibilities after Windows updates
  • Coverage across identity, files, servers, databases, NAS and Microsoft 365
  • On-premise platform: your audit data stays inside the organisation
Mitra Auditor
Central Panel
Active DirectoryActive Directory
Windows LogonWindows Logon
File ServerFile Server
Windows ServerWindows Server
SQL ServerSQL Server
PostgreSQLPostgreSQL
NAS SyslogNAS Syslog
Exchange OnlineExchange Online
SharePointSharePoint
TeamsTeams
CopilotCopilot
Power PlatformPower Platform

Frequently Asked Questions

Yes. Mitra Auditor covers on-premise infrastructure — Active Directory, File Server, SQL Server, PostgreSQL, NAS and Windows Server/Workstation — and Microsoft 365 services such as Exchange Online, SharePoint, Teams, Copilot, Power Platform and Azure Entra ID, all from a single centralised control panel.

The UBA engine learns each user's normal behaviour: hours, devices, file volumes, paths, applications, email, SharePoint and desktop activity. When it detects a significant deviation — out-of-hours activity, access to new paths, simultaneous sessions, privileged changes or anomalous operation volume — it generates an anomaly with a risk score and links it to other indicators to detect patterns such as exfiltration preparation, credential abuse or lateral movement.

Mitra Auditor provides traces and evidence to address the audit requirements of GDPR, the National Security Framework (ENS), ISO/IEC 27001, NIS2 and SOX. Compliance reports are available with filters by period, source, user and action type.

The Mitra Auditor server installation takes under an hour. On-premise module configuration is handled by an integrated wizard that automatically applies the necessary audit policies. Microsoft 365 modules require registering an application in Azure AD.

Most audit platforms display isolated events. Mitra Auditor automatically correlates events related to an incident, even when they come from different modules, and builds a chronological narrative: main actor, chain of actions, affected resources and potential impact.

Yes. Mitra Auditor is designed for complex enterprise environments: multiple Active Directory domains, several Microsoft 365 tenants, servers in different geographic locations and separate networks. Monitoring plans allow the audit to be organised by site, domain, source or criticality.

Mitra Auditor collects and stores events continuously. If an out-of-hours alert is configured, the system immediately notifies the relevant team and retains the event for subsequent analysis, forensic correlation and reporting.

Mitra Auditor is licensed via annual subscription, with a predictable model based on active modules and monitored infrastructure volume. It can be purchased independently or as part of the Mitra Data Security Suite.

Yes. The alerting engine allows rules to be created based on module, action type, user, device, time range and activity thresholds. Notifications can be delivered by email and Microsoft Teams.

Mitra Auditor is an on-premise IT audit platform that combines event auditing, Activity Inspector, forensic analysis, alerts, compliance reporting and user behaviour analytics in a single console. The goal is not to store logs: it is to turn scattered infrastructure activity into actionable evidence.