TamperDetect is a professional-grade change and tamper detection mechanism designed to protect your most valuable online information. Our intelligent monitoring provides the services needed to satisfy the new payment page change detection and script management requirements introduced in PCI DSS Version 4 Requirement 11.6.1.
TamperDetect is a service that helps you to identify and resolve unauthorized changes to online resources. Our advanced monitoring services are highly customizable to help you efficiently identify and resolve unauthorized changes to web pages, payment forms, account creation pages, and many other online resources that attackers are likely to change in the event of a compromise or attack..
File Integrity Monitoring (FIM) and TamperDetect both help you to identify changes to your website. However, TamperDetect provides many benefits beyond what is possible with FIM solutions. Our service is completely independent and out-of-band from your environment. This means that attackers are unable to disable or modify it in the event that your server is compromised. Additionally, TamperDetect is capable of monitoring content from all types of sources, including third-party content that is not possible to check with traditional FIM solutions.
Our intelligent monitoring and alerting services detect changes that could impact your most sensitive information such as credit card numbers, customer’s personally identifiable information, healthcare data, etc. Small changes to the code sent to browsers can have major impacts on where the data is sent, and how it is handled. Unlike traditional attack detection technologies, TamperDetect monitors web resources from the perspective of the browser. This allows us to sense changes that other solutions can’t. Our streamlined comparison tools allow you to find and review unanticipated changes with pinpoint accuracy.
Our services are used with all types of web pages and APIs. Generally speaking, any situation where critical information is handled will benefit from our monitoring services. For example, critical web pages, login pages, account creation pages, payment pages, information submission forms, and APIs are all common targets of attackers that our services can help you to monitor.
Our advanced notification options allow you to customize your notifications. Email, SMS Text, and Syslog can all be enabled as desired.
The objective of PCI DSS 11.6.1 matches up perfectly with the functionality of TamperDetect. Our services are deployed to alert your personnel to unauthorized modifications, including indicators of compromise, to security-impacting HTTP headers and script contents. When configured for your payment pages, the TamperDetect service will analyse the content provided to your customer’s browsers as often as you prefer.
Our US-based support is here to help you when you need it. We offer assistance with configuring your tamper detection service as well as PCI DSS consulting for those that have more involved assistance needs. Contact us at support@tamperdetect.com anytime!
Comparisons can be scheduled to run anywhere from hourly to monthly. We generally advise that you schedule the checks at least daily.