Advanced Endpoint Analysis policy expression reference
Expression format
CLIENT.APPLICATION (SCAN-type_ Product-id_ Method-name _ Method-comparator_ Method-param _…)
Expression strings
| Scan type | Scan type expression string |
|---|---|
| Anti-phishing | ANTIPHI |
| Antivirus | ANTIVIR |
| Backup Client | BACKUP |
| Citrix Workspace app (macOS) | MAC-CWA |
| Citrix Workspace app (Windows) | WIN-CWA |
| Data Loss Prevention | DATA-PREV |
| Firewall | FIREWALL |
| Health Agent | HEALTH |
| Hard disk Encryption | HD-ENC |
| Instant Messenger | IM |
| Web Browser | BROWSER |
| P2P | P2P |
| Patch Management | PATCH |
| MAC address (expression) | MAC |
| Domain check | DOMAIN |
| Registry Scan | REG |
| Windows Update Scan | WIN-UPDATE |
-
For macOS specific scans, expressions include the prefix
MAC-before the method type. Therefore, for antivirus and anti-phishing scans, the methods are MAC-ANTIVIR and MAC-ANTIPHI respectively. For example:client.application(MAC-ANTIVIR_2600_RTP_==_TRUE). -
The WIN-CWA scan is supported from Windows EPA library version 24.8.1.4 available at EPA library.
-
The MAC-CWA scan is supported from EPA client for macOS version 24.9.26 available at EPA client for macOS and mac_epa.tgz with OPSWAT version 4.3.3762 available at EPA.
Application scan methods
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| VERSION* | Specifies version of the application. | <, <=, >, >=, !=, == | Version string |
| AUTHENTIC** | Check if the application is authentic or not. | \== | TRUE |
| ENABLED | Check if the application is enabled. | \== | TRUE |
| RUNNING | Check if the application is running. | \== | TRUE |
| COMMENT | Comment field (ignored by scan). Delineated by [] within expressions. | \== | Any text |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| ENABLED-FOR | Check whether anti-phishing software is enabled for the selected application. | allof, anyof,noneof |
For Windows: Internet Explorer, Mozilla Firefox, Google Chrome, Opera, Safari. For Mac: Safari, Mozilla Firefox, Google, Chrome, Opera |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| RTP | Check whether the real-time protection is on or not. | \== | TRUE |
| SCAN-TIME | How many minutes since a full system scan was performed. | <, <=, >, >=, !=, == | Any positive number |
| VIRDEF-FILE-TIME | How many minutes since virus definition file was updated (that is, Number of minutes between virus definition file stamp and current timestamp). | <, <=, >, >=, !=, == | Any positive number |
| VIRDEF-FILE-VERSION | Version of definition file. | <, <=, >, >=, !=, == | Version string |
| ENGINE-VERSION | Engine version. | <, <=, >, >=, !=, == | Version string |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| LAST-BK-ACTIVITY | How many minutes since last backup activity was completed. | <, <=, >, >=, !=, == | Any positive number |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| ENABLED | Check whether the application is enabled or not and time protection is on or not on. | \== | TRUE |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| SYSTEM-COMPL | Check whether the system is in compliance. | \== | TRUE |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| ENC-PATH | PATH for checking encryption status. | NO OPERATOR | Any text |
| ENC-TYPE | Check whether the encryption type for the specified path. | allof, anyof, noneof |
List with the following options: UNENCRYPTED, PARTIAL, ENCRYPTED, VIRTUAL, SUSPENDED, PENDING |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| DEFAULT | Check whether set as the default browser. | \== | TRUE |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| SCAN-TIME | How many minutes since the last scan for the patch was performed. | <, <=, >, >=, !=, == | Any positive number |
| MISSED-PATCH | Client system is not missing patches of these types. | anyof, noneof |
ANY Pre-selected (Pre-selected patches on Patch Manager server) |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| ADDR | Check whether the client machine MAC addresses are or are not in the given list. | anyof, noneof |
Editable list |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| SUFFIX | Check whether the client machine exists or does not exist in the given list. | anyof, noneof |
Editable list |
| Method | Description | Comparator | Possible values |
|---|---|---|---|
| PATH | Path for registry check. In the format: HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Secure Access Client\EnableAutoUpdate. No escaping of special characters is required. All registry root keys: HKEY_LOCAL_MACHINE, HKEY_CURRENT_USER, HKEY_USERS, HKEY_CLASSES_ROOT, HKEY_CURRENT_CONFIG | NO OPERATOR | Any text |
| REDIR-64 | Follow 64-bit redirection. If set to TRUE, WOW redirection is followed (that is, Registry path is checked on 32-bit systems but WOW redirected path is checked for 64-bit systems.) If not set, WOW redirection is not followed (that is, the same registry path is checked for 32-bit and 64-bit systems.) For registry entries that are not redirected this setting has no effect. See the following article for the list of registry keys that get redirected on 64-bit systems: http://msdn.microsoft.com/en-us/library/aa384253%28v=vs.85%29.aspx |
== | TRUE |
| VALUE | Expected value for the above path. This scan works only for registry types of REG_DWORD and REG_QWORD. | <, <=, >, >=, !=, == | Any number |