TamperDetect is a professional-grade change and tamper detection mechanism designed to protect your most valuable online information. Our intelligent monitoring provides the services needed to satisfy the new payment page change detection and script management requirements introduced in PCI DSS Version 4 Requirement 11.6.1.
Learn how the Content Security Policy (CSP) helps protect a website from attacks like XSS by restricting the sources from which content can be loaded.
Most businesses don't fully understand or implement headers in order to keep their site safe.
Looks safe right?...check again, learn how attackers can hide code or sensitive information inside something that appears completely ordinary.
TamperDetect is a service that helps you to identify and resolve unauthorized changes to online resources. Our advanced monitoring services are highly customizable to help you efficiently identify and resolve unauthorized changes to web pages, payment forms, account creation pages, and many other online resources that attackers are likely to change in the event of a compromise or attack..
Web Page Integrity Monitoring and TamperDetect both help you to identify changes to your website. However, TamperDetect provides many benefits beyond what is possible with FIM solutions. Our service is completely independent and out-of-band from your environment. This means that attackers are unable to disable or modify it in the event that your server is compromised. Additionally, TamperDetect is capable of monitoring content from all types of sources, including third-party content that is not possible to check with traditional web page integrity monitoring solutions.
Our intelligent monitoring and alerting services detect changes that could impact your most sensitive information such as credit card numbers, customer’s personally identifiable information, healthcare data, etc. Small changes to the code sent to browsers can have major impacts on where the data is sent, and how it is handled. Unlike traditional attack detection technologies, TamperDetect monitors web resources from the perspective of the browser. This allows us to sense changes that other solutions can’t. Our streamlined comparison tools allow you to find and review unanticipated changes with pinpoint accuracy.
Our services are used with all types of web pages and APIs. Generally speaking, any situation where critical information is handled will benefit from our monitoring services. For example, critical web pages, login pages, account creation pages, payment pages, information submission forms, and APIs are all common targets of attackers that our services can help you to monitor.
Our advanced notification options allow you to customize your notifications. Email, SMS Text, and Syslog can all be enabled as desired.
The objective of PCI DSS 11.6.1 matches up perfectly with the functionality of TamperDetect. Our services are deployed to alert your personnel to unauthorized modifications, including indicators of compromise, to security-impacting HTTP headers and script contents. When configured for your payment pages, the TamperDetect service will analyse the content provided to your customer’s browsers as often as you prefer.
Our US-based support is here to help you when you need it. We offer assistance with configuring your tamper detection service as well as PCI DSS consulting for those that have more involved assistance needs. Contact us at support@tamperdetect.com anytime!
Comparisons can be scheduled to run anywhere from hourly to monthly. We generally advise that you schedule the checks at least daily.