Quantcast
Viewing all articles
Browse latest Browse all 1863

How to check specific process with Host Integrity Policy

Is it possible to monitor specific progress status with Host Integrity (HI) policy in endpoint protection? The answer is yes.

Here is a simple example of how to set the requirement in HI policy.

Details steps as below:

1. Edit HI policy--> click Requirements--> click "add" button--> select client platform: Windows and select "Custom requirement", click Ok:

Image may be NSFW.
Clik here to view.
1.png

2. On the custom requirement page, click add--> IF..THEN,

Image may be NSFW.
Clik here to view.
2_1_1.jpeg

2.2. Under THEN--> add Function Utility: log message, and input message under log description: cmd running:

Image may be NSFW.
Clik here to view.
2_2_0.png

2.3. Under THEN, add ELSE, Under ELSE--> add Function Utility: log message, and input message under log description:cmd not running:

Image may be NSFW.
Clik here to view.
2_3_0.png

Image may be NSFW.
Clik here to view.
3_1.png

Open Endpoint Protection Manager console--> Monitors--> Logs--> Log type: Compliance, Log content: Client Host Integrity--> view log

The same HI event logs present. Besides, you can view Details for more information about the specific event as below.

Image may be NSFW.
Clik here to view.
3_2.png


Viewing all articles
Browse latest Browse all 1863

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>