Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Process checks in Trust Profile

In this document
  • General Notes
  • Process Running (by path)
  • Process Running (by name)
  • Finding a Process Path

Process checks ask whether a program is currently running on the endpoint. They are the usual way to require that an EDR, antivirus or management agent is not only installed but active.

Supported platforms: [Windows, macOS]

General Notes

  • Both checks use glob patterns (* for any run of characters, ? for a single character) and are not case sensitive.

  • The agent refreshes its list of running processes at most every five seconds, so a process that has just started or stopped may take a few seconds to be seen.

  • Use one check with a pattern that covers what you need rather than two checks that must find the same process. Two separate checks may be satisfied by two different processes.

  • If the agent is denied access to a process whose path might match, the check reports an error instead of a false result.

trust profile process check

Process Running (by path)

Platforms

[Windows, macOS]

Comparison

None

Fields

Image path (required)

Passes when a running process was started from a location that matches the pattern. The pattern is matched against the full path of the program file, so it must describe the whole path, not just the name.

Pattern Result Why

falcond

Fails

Not a path. Nothing ends up matching a bare name.

*falcond

Passes

Any path that ends in falcond.

*\CSFalconService.exe

Passes

Any Windows path whose file name is CSFalconService.exe.

C:\Program Files\CrowdStrike\CSFalconService.exe

Passes

The exact path.

Examples
  • Windows: *\CSFalconService.exe or C:\Program Files\Vendor\*.exe

  • macOS: /Library/CS/falcond or /Applications/Vendor.app/Contents/MacOS/*

Tip
This is the stronger of the two process checks. Anyone can rename a program to look like your EDR, but it can’t run from your EDR’s protected install folder without admin rights. Prefer the full install path when you know it.

Process Running (by name)

Platforms

[Windows, macOS]

Comparison

None

Fields

Process name (required)

Passes when a running process has a name that matches the pattern. Only the program’s file name is compared, without its folder.

Examples
  • falcond

  • CSFalcon*

  • MsMpEng.exe

On Windows the process name includes the extension, for example MsMpEng.exe. Use MsMpEng* if you want to match it without typing the extension.

Note
This check is weaker than Process Running (by path). A process name is easy to fake by renaming a file. Use it only when the install path varies between devices or is not known.

Finding a Process Path

  • Windows: in Task Manager > Details, right-click the column header, choose Select columns and enable Image path name. You can also run this in PowerShell: Get-Process -Name <name> | Select-Object Path.

  • macOS: in Activity Monitor, double-click the process and open Open Files and Ports. The first entry is the program’s path. You can also run this in Terminal: ps -axo comm | grep -i <name>.

www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013