Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

File checks in Trust Profile

In this document
  • General Notes
  • File or directory exists
  • Path is a file
  • Path is a directory
  • Path is executable
  • File MD5 digest equals
  • File SHA1 digest equals
  • File SHA256 digest equals

File checks ask whether a file or folder is present on the endpoint and, optionally, whether a file is exactly the one you expect. Use them to confirm that security software is installed, that a company certificate or configuration file is in place, or that a binary has not been replaced.

Supported platforms: [Windows, macOS]

General Notes

  • Enter the full path, starting from the drive on Windows (C:\) or from / on macOS. File checks take exact paths, not patterns.

  • Type Windows paths with single backslashes, the way Explorer shows them. DefensX escapes them when it builds the profile.

  • A path that doesn’t exist makes the check fail.

  • If the agent cannot look at the path, the check reports an error and the endpoint does not pass. This usually means a folder along the way denied access. A device is never allowed through because it couldn’t be inspected.

trust profile file check

File or directory exists

Platforms

[Windows, macOS]

Comparison

None

Fields

Path (required)

Passes when anything exists at the path: a file, a folder or a link to either. Links are followed.

Examples
  • Windows: C:\Program Files\CrowdStrike\CSFalconService.exe

  • macOS: /Applications/Falcon.app/Contents/MacOS/Falcon

Path is a file

Platforms

[Windows, macOS]

Comparison

None

Fields

Path (required)

Passes when the path exists and is a regular file, not a folder.

Path is a directory

Platforms

[Windows, macOS]

Comparison

None

Fields

Path (required)

Passes when the path exists and is a folder.

Example
  • macOS: /Library/Application Support/Vendor

Path is executable

Platforms

[Windows, macOS]

Comparison

None

Fields

Path (required)

Passes when the path is an executable file. This describes the file itself, not whether the current user may run it. On Windows the file extension decides it (for example .exe). On macOS the file’s execute permission decides it.

File MD5 digest equals

Platforms

[Windows, macOS]

Comparison

None

Fields

Path (required), MD5 (required, 32 hex characters)

Passes when the file at the path exists and its MD5 hash equals the value you enter.

File SHA1 digest equals

Platforms

[Windows, macOS]

Comparison

None

Fields

Path (required), SHA1 (required, 40 hex characters)

Passes when the file’s SHA1 hash equals the value you enter.

File SHA256 digest equals

Platforms

[Windows, macOS]

Comparison

None

Fields

Path (required), SHA256 (required, 64 hex characters)

Passes when the file’s SHA256 hash equals the value you enter.

To get a file’s SHA1, SHA256 or MD5 hash:

  • Windows (PowerShell): Get-FileHash "C:\Path\To\file.exe" -Algorithm SHA1 (you can also use MD5 or SHA256 as Algorithm parameter)

  • macOS (Terminal): shasum -a 1 /path/to/file (you can also use shasum -a 256 or md5sum respectively)

Note
A hash changes every time the software is updated. A digest check pinned to one build will fail after the next update. Use it for files that should never change, and use Path is a file or a version check for software that updates regularly.
www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013