Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Registry checks in Trust Profile

In this document
  • General Notes
    • Writing the Key
    • Value Names
  • Registry key exists
  • Registry value exists
  • Registry Value

Registry checks read the Windows Registry. Almost every Windows setting, Group Policy and management tool leaves a trace there, so these checks can verify things no dedicated check covers. Examples are a Group Policy setting, a browser policy or a vendor’s configuration flag.

Supported platforms: [Windows]

General Notes

Writing the Key

You can write the hive in its long or short form, and a path copied from Registry Editor works as pasted. That includes a leading Computer\.

Long form Short form

HKEY_LOCAL_MACHINE\

HKLM\

HKEY_CURRENT_USER\

HKCU\

HKEY_USERS\

HKU\

HKEY_CLASSES_ROOT\

HKCR\

HKEY_CURRENT_CONFIG\

HKCC\

A key without a hive is read under HKEY_LOCAL_MACHINE.

Important
The DefensX Agent runs as a Windows service, so HKEY_CURRENT_USER refers to the service account, not the person signed in. To check a per-user setting, use HKEY_USERS\<user SID>.... For machine-wide policies, use HKEY_LOCAL_MACHINE.

Value Names

The Value name field accepts:

  • an exact value name, for example EnableFirewall

  • a glob pattern, for example Ext*

  • __ANY__ to look at every value under the key

With a pattern or __ANY__, the check passes when at least one matching value satisfies it. This is how Windows stores list policies, such as a key with values named 1, 2, 3. Only values directly under the key are looked at. Subkeys are not searched.

trust profile registry check

Registry key exists

Platforms

[Windows]

Comparison

None

Fields

Key (required)

Passes when the registry key exists.

Example
  • HKLM\SOFTWARE\CrowdStrike

Registry value exists

Platforms

[Windows]

Comparison

None

Fields

Key (required), Value name (required)

Passes when a value with that name exists under the key. The value’s data and type are not read.

Use it with Registry Value when a value may be missing, so that you decide what happens in that case. See the notes below.

Registry Value

Platforms

[Windows]

Comparison

equals, does not equal, is less than, is less than or equal, is greater than, is greater or equal, starts with, ends with, contains, matches (glob)

Fields

Key (required), Value name (required), Compared with (required)

Reads a registry value and compares it with the text in Compared with.

Table 1. How the value type affects the comparison
Registry type Comparison

REG_SZ, REG_EXPAND_SZ (text)

equals and does not equal compare text without regard to case. The ordering comparisons are version-aware, so 1.9 is less than 1.10. This lets you compare a version stored as text directly.

REG_DWORD, REG_QWORD (numbers)

Compared as numbers. Enter the number in decimal, for example 1. 0x1f is also read as hex, but avoid leading zeros: 010 is read as octal (8).

REG_MULTI_SZ, REG_BINARY and other types

Cannot be compared. The check reports an error. With a pattern or __ANY__, values of these types are skipped.

Table 2. Examples
Key Value name Comparison Compared with

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile

EnableFirewall

equals

1

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion

DisplayVersion

equals

23H2

HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist

__ANY__

starts with

<extension ID>

When the value is missing

If the key or the value does not exist, Registry Value fails for every comparison, including does not equal.

  • To require value exists and is not X: add Registry value exists and Registry Value does not equal X, with the group set to Match all checks.

  • To accept value is missing, or is not X: use NOT Registry Value equals X.

Note
With a pattern or __ANY__, NOT Registry Value equals X means no matching value equals X. There is no way to ask whether not every value equals X.
www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013