Docs

Quickstart

Scope critical paths, approve a baseline, and receive your first integrity alert.

Quickstart

Get from a connected host to live File Integrity Monitoring in a few minutes.

1. Scope critical paths

Open Baselines → New policy and add the paths that matter most:

  • System binaries and shared libraries
  • Application configs and secrets mounts
  • Web roots and deployment artifacts
  • Certificate and key directories

Start narrow. Expand coverage after alerts are tuned.

2. Capture and approve a baseline

Run an initial scan, review the inventory, then approve the known-good state. Bitfy only treats later differences as integrity events once a baseline is approved.

3. Confirm alert delivery

Send a controlled test change to a scoped file and verify:

  • The event appears in the change feed
  • Severity and path context look correct
  • Notifications reach your preferred channel

4. Export evidence

From Compliance, generate a sample FIM evidence pack to confirm reporting works for your audit workflow.

You are ready for production monitoring. Continue with Agents for host-scale configuration.