<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in the Bitdefender Integrity Monitoring Add-On?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Real-time change monitoring</strong> – Detects changes to monitored entities as they occur on endpoints.<br /> <strong>Default and custom rules</strong> – Bitdefender supplies default rules; you add file and registry rules.<br /> <strong>Automatic corrective actions</strong> –Restores permissions, owners and registry values after unauthorised changes.<br /> <strong>Three performance modes</strong> – Fast, Normal and Slow buffering to control endpoint load.<br /> <strong>Event reports and export</strong> – Filter by severity, user or entity; export CSV and PDF.<br /> <strong>Important</strong> – No macOS agent support; the module runs on Windows and Linux.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of the Bitdefender Integrity Monitoring Add-On?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Bitdefender lists this module as GravityZone Integrity Monitoring, and it extends an existing GravityZone endpoint deployment with system-wide change monitoring across files, directories, registry keys, installed software, services and user accounts. Rules, events and reports are managed centrally from the GravityZone cloud console, so no separate integrity tool has to be operated alongside the endpoint agent.<br /><br /> <strong>Detects silent changes</strong> – Catches configuration edits that antivirus and EDR rules ignore.<br /> <strong>One agent</strong> – Reuses the installed Bitdefender agent instead of a second sensor.<br /> <strong>Audit-ready change records</strong> – Each event names the entity, the change and the user.<br /> <strong>Alert noise control</strong> – Restrictors block over-broad rules that would flood the event list.<br /> <strong>Tunable endpoint impact</strong> – Buffering profiles let busy servers trade alert speed for load.<br /> <strong>Selectable event retention</strong> – Seven days by default, longer through a retention add-on.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where built-in Windows protection stops and which security layers a business has to add itself.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is the Bitdefender Integrity Monitoring Add-On suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether you operate Windows or Linux servers holding regulated or business-critical data, and whether anyone outside your IT team ever asks you to prove that those systems were not altered. A three-person company running a payment-adjacent Linux server has a stronger case for this module than a fifty-person company whose data lives entirely in a hosted service.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Windows or Linux servers in scope</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-server-2025-vs-2022-vs-2019"><strong>Windows Server 2025 vs. 2022 vs. 2019: Is It Worth Upgrading?</strong><br />Compares the current Windows Server versions and helps you decide which server platform your protected workloads should run on.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the Bitdefender Integrity Monitoring Add-On meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Swiss Information Security Act applies to operators of critical infrastructure, not to every company, so a regional retailer or agency is normally outside its scope while an energy supplier, hospital or larger public-sector IT operator is inside it. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. The Integrity Monitoring Add-On supports that deadline in one specific way: each event records the affected entity, the type of change and the user account that made it, which is the material you need to describe what happened rather than only that something happened. It does not detect the attack itself, does not decide whether an event is reportable, and sends nothing to BACS, so the discovery and the report remain a human process and the module contributes evidence rather than compliance. This information is a general explanation and not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the Bitdefender Integrity Monitoring Add-On meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product makes an organisation NIS 2 compliant, because the directive addresses governance, processes and accountability alongside technical measures. The NIS 2 Directive requires risk-management measures from essential and important entities in areas such as incident handling, business continuity, supply chain security, security in system acquisition, development and maintenance, and policies for assessing whether those measures actually work. The Integrity Monitoring Add-On contributes to two of these categories: it supplies detection material for incident handling, and it produces the change records that let you test whether a hardening measure stayed in place after it was applied. It contributes nothing to business continuity, supplier assessment, access governance or staff training, and it raises no incident notification of its own. Treat it as one technical control inside a wider measure catalogue, not as the answer to a NIS 2 gap analysis.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the Bitdefender Integrity Monitoring Add-On help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for a narrow and clearly defined set of questions. It answers items on change detection for critical systems, on whether unauthorised modifications are recorded with attribution to a user account, on whether unauthorised changes can be reversed automatically, and on how long change records are kept. Questions about central policy management and role-based administrator access are answered by the underlying GravityZone console rather than by the add-on itself. It answers nothing on encryption at rest, backup and restore, patch levels, mailbox protection, mobile device management, penetration testing, staff awareness or supplier due diligence, and it is not a substitute for a security information and event management system. Where those gaps matter, the cheaper route is usually to stay inside the GravityZone family and add the Patch Management or Full Disk Encryption modules, or move to a higher Business Security tier that already includes endpoint detection and response, because a second vendor means a second console and a second evidence trail to maintain at audit time.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the standard event storage and the Data Retention add-on?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The single decisive difference is how far back you can look. Integrity Monitoring stores its events for seven days by default, which is enough to investigate something you noticed this week but not enough to answer a question about a change that happened last quarter. Bitdefender offers a separate Data Retention add-on that extends event storage to 90 days, 180 days or one year. If your reason for buying is an audit, a customer questionnaire or a regulated framework that expects historical change records, the seven-day default will not carry that use case on its own.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Standard</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">With Data Retention add-on</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Event storage period</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">7 days</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">90, 180 or 365 days</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Investigating a recent change</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Retrospective audit evidence</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Requires the Integrity Monitoring module</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is an add-on, not a standalone product: it needs an existing GravityZone endpoint security product underneath it and is administered from the GravityZone cloud console, so it is not a fit if you were planning to run it next to a different vendor's endpoint agent. Agent support covers Windows and Linux only, which means Macs in your fleet stay outside the monitoring scope entirely, and on Linux only endpoints using the kprobes system sensor are supported, so older or unusual kernels can fall out of coverage. Custom rules can target files, directories, registry keys and registry values, while services, installed software and user accounts are watched through Bitdefender's default rules rather than rules you write yourself, which matters if your audit expects a specific named service to be monitored. The most common follow-up purchase is the Data Retention add-on, because the seven-day default storage is discovered to be too short at the moment someone asks for historical evidence. Finally, this module detects and reverses changes but does not restore lost data, so it does not reduce your need for a working backup.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Explains why change detection and backup solve different problems and what a working restore process needs to cover.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about the Bitdefender Integrity Monitoring Add-On</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does this replace an EDR solution?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. Endpoint detection and response looks for attacker behaviour and known patterns, while Integrity Monitoring compares monitored entities against a known-good baseline and flags any deviation regardless of cause. That is why it catches things an EDR can miss, such as an administrator weakening a security setting on a server, but it also means it has no threat hunting, no incident timeline and no response playbooks of its own.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Will it flood my inbox with alerts?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Two mechanisms work against that. Restrictors refuse to accept rules that are too broad to be useful, such as monitoring every log file on an endpoint, and the Normal and Slow processing profiles buffer events for three or six seconds so duplicate changes are collapsed before an alert is raised. Events also carry a severity of low, medium, high or critical, so you can filter the event list down to what actually needs a human.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it undo a change automatically?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, and you decide per rule whether the action is automatic or manual. For files and directories it can delete files that should not have been created and correct changes to attributes, permissions, owner, group, file name and hash. For the Windows registry it can delete unwanted keys and sub-keys and correct deleted or modified keys and values.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-server,sec-endpoint,compliance-supplier" data-audience="b2b" data-count="3"> </div>