This article lists every check you can add to a trust profile, grouped by the categories used in the Add a check menu, with the platforms that support each one. Each category has its own article with full details.
| Platform |
Checks available |
Windows |
File, Process, Application, Registry, Security, Operating System, Domain, Versions |
macOS |
File, Process, Property List, Security, Operating System, Domain, Versions |
iOS |
None. The platform can only be allowed or blocked. |
Android |
None. The platform can only be allowed or blocked. |
Generic (every platform) |
Network (IP Country) |
All Checks at a Glance
| Category |
Check |
Platforms |
File |
File or directory exists |
[Windows, macOS] |
File |
Path is a file |
[Windows, macOS] |
File |
Path is a directory |
[Windows, macOS] |
File |
Path is executable |
[Windows, macOS] |
File |
File MD5 digest equals |
[Windows, macOS] |
File |
File SHA1 digest equals |
[Windows, macOS] |
File |
File SHA256 digest equals |
[Windows, macOS] |
Process |
Process Running (by path) |
[Windows, macOS] |
Process |
Process Running (by name) |
[Windows, macOS] |
Application |
Application is Installed |
[Windows] |
Application |
Application Version |
[Windows] |
Registry |
Registry key exists |
[Windows] |
Registry |
Registry value exists |
[Windows] |
Registry |
Registry Value |
[Windows] |
Property List |
Preference domain exists |
[macOS] |
Property List |
Preference key exists |
[macOS] |
Property List |
Preference key |
[macOS] |
Security |
Firewall is enabled |
[Windows] |
Security |
BitLocker protection is on |
[Windows] |
Security |
BitLocker drive is encrypted |
[Windows] |
Security |
BitLocker encryption method |
[Windows] |
Security |
Antivirus is installed |
[Windows] |
Security |
Antivirus is enabled |
[Windows] |
Security |
Antivirus is up to date |
[Windows] |
Security |
FileVault is enabled |
[macOS] |
Operating System |
Windows build number |
[Windows] |
Operating System |
Reboot is pending |
[Windows] |
Operating System |
Reboot is required |
[Windows] |
Operating System |
An OS update is available |
[Windows] |
Operating System |
macOS Release Version |
[macOS] |
Operating System |
Darwin (kernel) version |
[macOS] |
Domain |
Windows Machine Role |
[Windows] |
Domain |
Windows AD Domain DNS Name |
[Windows] |
Domain |
Windows AD Domain NETBIOS Name |
[Windows] |
Domain |
Windows AD Domain GUID |
[Windows] |
Domain |
EntraID Join Type |
[Windows] |
Domain |
EntraID Device Joined Tenant ID |
[Windows] |
Domain |
macOS machine role |
[macOS] |
Network |
IP Country |
[Generic: Windows, macOS, iOS, Android] |
Comparisons
Checks that compare a value have a drop-down next to their name. Depending on the check, the options are:
| Comparison |
Used for |
equals, does not equal |
Names and identifiers: countries, machine roles, domain names, GUIDs, join types, encryption methods. Also available on all version and text checks. |
is less than, is less than or equal, is greater than, is greater or equal |
Versions and numbers: DefensX Agent Version, Windows build number, macOS versions, Application Version, Registry Value, Preference key. |
starts with, ends with, contains, matches (glob) |
Text values. Only on Registry Value and Preference key. |
Version comparisons work number by number, so 1.10 is higher than 1.9, and a missing part counts as zero (14.5 is the same as 14.5.0).
Patterns (Glob)
Several fields accept a glob pattern:
-
* matches any run of characters.
-
? matches exactly one character.
-
A value without * or ? must match exactly.
Patterns are not case sensitive. For example, Mozilla Firefox* matches Mozilla Firefox (x64 en-US).
Things to Keep in Mind
-
NOT reverses a check. Tick NOT to require the opposite. For example, NOT Reboot is required passes only on computers that don’t need a restart.
-
Missing is not the same as different. For comparison checks on a registry value, a preference key, an installed application or a domain name, a value that doesn’t exist at all makes both equals and does not equal fail. Add the matching exists or installed check if you need to decide what happens when the value is missing.
-
Errors never pass. If the agent cannot inspect something a check needs, the whole profile fails on that endpoint. An example is a folder it is refused access to. The Online Check detail page shows the reason.
-
Prefer positive checks. If a check name is unknown to an older agent, it answers false. Under NOT, a false turns into a pass. Keep agents up to date when you use newer checks.
|