Endpoint Protection

 View Only

How to check specific process with Host Integrity Policy 

May 08, 2017 12:07 PM

Is it possible to monitor specific progress status with Host Integrity (HI) policy in endpoint protection? The answer is yes.

Here is a simple example of how to set the requirement in HI policy.


Details steps as below:


1. Edit HI policy--> click Requirements--> click "add" button--> select client platform: Windows and select "Custom requirement", click Ok:

1.png

2. On the custom requirement page, click add--> IF..THEN,

2.1. Under IF--> select a condition: Utility: Process is running and input process file name, here for example cmd.exe or c:\windows\cmd.exe:

2_1_1.jpeg

2.2. Under THEN--> add Function Utility: log message, and input message under log description: cmd running:

 

 

2_2_0.png

2.3. Under THEN, add ELSE, Under ELSE--> add Function Utility: log message, and input message under log description:cmd not running:

2_3_0.png

Keep other HI policy settings as default, assign the HI policy to specific group.

 
3. Test HI policy as below:

3.1. Run cmd.exe manually.

3.2. open SEP UI--> view log--> click view logs by client management--> view security log as  below:

Host Integrity message shows up and message is "cmd running".

3_1.png

Open Endpoint Protection Manager console--> Monitors--> Logs--> Log type: Compliance, Log content: Client Host Integrity--> view log


The same HI event logs present. Besides, you can view Details for more information about the specific event as below.

3_2.png

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Related Entries and Links

No Related Resource entered.