Advanced Endpoint Analysis policy expression reference
Expression format
CLIENT.APPLICATION (SCAN-type_ Product-id_ Method-name _ Method-comparator_ Method-param _…)
Expression strings
| Scan type | Scan type expression string |
|---|---|
| Anti-phishing | ANTIPHI |
| Antispyware | ANTISPY |
| Antivirus | ANTIVIR |
| Backup Client | BACKUP |
| Device Access Control | DEV-CONT |
| Data Loss Prevention | DATA-PREV |
| Desktop Sharing | DESK-SHARE |
| Firewall | FIREWALL |
| Health Agent | HEALTH |
| Hard disk Encryption | HD-ENC |
| Instant Messenger | IM |
| Web Browser | BROWSER |
| P2P | P2P |
| Patch Management | PATCH |
| URL Filtering | URL-FILT |
| MAC address (expression) | MAC |
| Domain check | DOMAIN |
| Registry Scan | REG |
Application scan methods
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| VERSION* | Specifies version of the application. | <, <=, >, >=, !=, == | Version string |
| AUTHENTIC** | Check if the application is authentic or not. | \== | TRUE |
| ENABLED | Check if the application is enabled. | \== | TRUE |
| RUNNING | Check if the application is running. | \== | TRUE |
| COMMENT | Comment field (ignored by scan). Delineated by [] within expressions. | \== | Any text |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| ENABLED-FOR | Check whether anti-phishing software is enabled for the selected application. | allof, anyof,noneof |
For Windows: Internet Explorer, Mozilla Firefox, Google Chrome, Opera, Safari. For Mac: Safari, Mozilla Firefox, Google, Chrome, Opera |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| RTP | Check whether the real-time protection is on or not. | \== | TRUE |
| SCAN-TIME | How many minutes since a full system scan was performed. | <, <=, >, >=, !=, == | Any positive number |
| VIRDEF-FILE-TIME | How many minutes since virus definition file was updated (that is, Number of minutes between virus definition file stamp and current timestamp). | <, <=, >, >=, !=, == | Any positive number |
| VIRDEF-FILE-VERSION | Version of definition file. | <, <=, >, >=, !=, == | Version string |
| ENGINE-VERSION | Engine version. | <, <=, >, >=, !=, == | Version string |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| LAST-BK-ACTIVITY | How many minutes since last backup activity was completed. | <, <=, >, >=, !=, == | Any positive number |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| ENABLED | Check whether the application is enabled or not and time protection is on or not on. | \== | TRUE |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| SYSTEM-COMPL | Check whether the system is in compliance. | \== | TRUE |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| ENC-PATH | PATH for checking encryption status. | NO OPERATOR | Any text |
| ENC-TYPE | Check whether the encryption type for the specified path. | allof, anyof, noneof |
List with the following options: UNENCRYPTED, PARTIAL, ENCRYPTED, VIRTUAL, SUSPENDED, PENDING |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| DEFAULT | Check whether set as the default browser. | \== | TRUE |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| SCAN-TIME | How many minutes since the last scan for the patch was performed. | <, <=, >, >=, !=, == | Any positive number |
| MISSED-PATCH | Client system is not missing patches of these types. | anyof, noneof |
ANY Pre-selected (Pre-selected patches on Patch Manager server) |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| ADDR | Check whether the client machine MAC addresses are or are not in the given list. | anyof, noneof |
Editable list |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| SUFFIX | Check whether the client machine exists or does not exist in the given list. | anyof, noneof |
Editable list |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| PATH | Path for registry check. In the format: HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Secure Access Client\EnableAutoUpdate. No escaping of special characters is required. All registry root keys: HKEY_LOCAL_MACHINE, HKEY_CURRENT_USER, HKEY_USERS, HKEY_CLASSES_ROOT, HKEY_CURRENT_CONFIG | NO OPERATOR | Any text |
| REDIR-64 | Follow 64-bit redirection. If set to TRUE, WOW redirection is followed (that is, Registry path is checked on 32-bit systems but WOW redirected path is checked for 64-bit systems.) If not set, WOW redirection is not followed (that is, the same registry path is checked for 32-bit and 64-bit systems.) For registry entries that are not redirected this setting has no effect. See the following article for the list of registry keys that get redirected on 64-bit systems: http://msdn.microsoft.com/en-us/library/aa384253%28v=vs.85%29.aspx |
== | TRUE |
| VALUE | Expected value for the above path. This scan works only for registry types of REG_DWORD and REG_QWORD. | <, <=, >, >=, !=, == | Any number |