Skip to content
The platform · LT AuditorMP®

One powerful way to see, track and respond.

LT AuditorMP® is a multi-platform cybersecurity and compliance solution. It continuously monitors user behavior, file activity, identity changes and suspicious events across Windows, Linux, macOS and hybrid cloud environments, and generates standardized, customizable reporting for the frameworks that matter.

Deploy on Windows, Linux, and macOS in on-prem environments. Gain centralized visibility into Microsoft Active Directory, Microsoft Entra ID (including Azure sign-in activity), Windows logon events, file and folder activity across Windows, Linux, and macOS systems, OpenText eDirectory and NSS file systems, and perimeter network devices, all from a single platform.

Detect · Investigate · Prove

Don’t just secure it. Demonstrate your compliance.

Real-time visibility. Instant compliance reporting. Auditor-ready evidence. LT AuditorMP® transforms security data into the proof your organization needs, automatically.

Illustrative interface. Live deployments report on your own environment and controls.

Identity & access security

Identity is your first line of defense.

Track user and group changes, uncover excessive permissions and identity vulnerabilities, and gain continuous visibility into the activity that matters most for protecting your organization.

Identity activityAD · ENTRA ID
Group membership changed · Domain AdminsREVIEW
Failed logon · 6 attempts · service accountALERT
Entra ID sign-in · new locationREVIEW
Password policy applied · Finance OUOK
File & data protection

Know who accessed what, and when.

Monitor file and folder access, detect permission changes, and discover sensitive data across your environment. LT AuditorMP® provides the visibility needed to reduce risk, protect critical information, and maintain compliance.

Sensitive data exposure3 SHARES
\\FS01\FinanceHIGH
\\FS01\HRMEDIUM
\\FS02\SharedLOW
247 files with excessive permissions · 18 folders with unscanned PII
Cloud & hybrid visibility

One platform. Every environment.

Monitor Microsoft Entra ID, Azure sign-in activity, AWS, Google Workspace, and on-prem systems from a single platform. LT AuditorMP® delivers consistent visibility across hybrid environments, helping security teams detect risk wherever it occurs.

On-premises
Windows & Linux
Cloud
Azure & Entra ID
Directory
OpenText eDirectory
File system
OpenText NSS
Threat detection & forensics

See threats. Understand impact. Respond faster.

LT AuditorMP® correlates events across your environment, detects suspicious activity, and preserves the forensic evidence needed for rapid investigations. When leadership asks what happened, how serious it is, and what actions to take, your team has answers backed by data.

Threat detected
14:22 UTC
Anomalous access pattern
14:22:07  perimeter.fw01  flagged
14:22:09  user=j.doe  files=312  burst
14:22:11  dest=external  blocked
Forensic record #A-7741 saved
Frequently asked · On the record

Straight answers about proving security.

What LT AuditorMP® does, who it is built for, and how it provides compliance reporting.

What is LT AuditorMP®?

LT AuditorMP® is Blue Lance 2.0's unified security auditing, compliance, and monitoring platform. It continuously monitors user activity, file and data access, identity changes, and suspicious events across Windows, Linux, macOS, and hybrid cloud environments. By correlating security events and mapping them to frameworks such as NIS 2, HIPAA, PCI DSS, FFIEC, GDPR, DORA, and ISO 27001, LT AuditorMP® delivers the real-time visibility, forensic evidence, and audit-ready reports organizations need to strengthen security and demonstrate compliance.

How does Blue Lance 2.0 help prove compliance to an auditor?

Blue Lance turns continuous monitoring into evidence. LT AuditorMP® records who accessed what, when identities and permissions changed, and how suspicious activity was handled, then exports standardized, framework-mapped reports on demand. When an auditor asks for proof, the evidence bundle is already assembled instead of reconstructed after the fact.

What is privileged user and file activity monitoring?

Privileged user and file activity monitoring provides continuous visibility into who has elevated access, what actions they perform, and how sensitive data is accessed or changed. LT AuditorMP® monitors administrative accounts, permission changes, privileged logons, file and folder activity, and other critical security events across on-premises and cloud environments. The result is faster threat detection, stronger accountability, and the audit-ready evidence needed to demonstrate security and compliance.

Which compliance frameworks does LT AuditorMP® support?

LT AuditorMP® includes prebuilt reporting templates for NIS 2, GDPR, DORA, ISO 27001, HIPAA, PCI DSS, FFIEC, FDIC, NIST and other leading frameworks. Because every organization has unique compliance obligations, its reporting engine is fully customizable, enabling you to create reports that align with internal policies, customer requirements, and local or industry-specific regulations.

What platforms and environments does LT AuditorMP® monitor?

LT AuditorMP® monitors Windows, Linux, macOS, and hybrid cloud environments from a single platform. It collects and correlates activity from Microsoft Active Directory, Microsoft Entra ID, Azure, AWS, Google Workspace, file systems, operating systems, network devices, and other enterprise data sources. Its flexible collection framework enables organizations to extend monitoring to additional platforms and applications, providing centralized visibility across the entire IT environment.

What is the difference between securing a network and proving it?

Securing a network means deploying controls to prevent and detect threats. Proving it means demonstrating, with evidence, that those controls work and are enforced. Blue Lance does both: LT AuditorMP® detects the activity that matters and produces the audit-ready proof that regulators and customers require. Secure it, then prove it.

Implementation & support

More than software. A complete solution.

Successful security deployments require more than technology. LT AuditorMP® combines powerful monitoring and compliance capabilities with guided implementation, comprehensive documentation, and direct access to Blue Lance 2.0 technical experts to help you deploy with confidence and maximize value.

Guided implementation

Automated deployment tools, implementation utilities, and comprehensive online documentation help you install, configure, and begin monitoring quickly.

Expert technical support

Work directly with Blue Lance 2.0 technical specialists for deployment guidance, advanced configuration, troubleshooting, and best practices whenever additional expertise is needed.

Subscription benefits

Your subscription includes software updates, feature enhancements, service packs, security fixes, and responsive phone and email support to keep your environment secure and up to date.