Fortinet white logo
Fortinet white logo

Administration Guide

Windows Custom Scan

Windows Custom Scan

The custom scans feature allows you to search host computers for very specific information. Custom scans must be created separately for different operating systems. Within each operating system, there are different types of scans that can be created. Refer to Add A Windows Custom Scan below for a list of scan types and general instructions on adding scans. Refer to the instructions for each scan type for field level information. You can modify or delete the scans at any time. When a scan is modified, it affects any existing scan that use that custom scan.

Add a custom scan
  1. Click Policy & Objects.
  2. Expand Endpoint Compliance.
  3. Click the Scans option to select it.
  4. Click Custom Scans.
  5. Select Add.
  6. Select Windows from the Operating System drop-down list.
  7. Select the type of scan desired. Each scan type has a special set of fields that are specific to that type. Use the table below for settings.

    Type

    Description

    Cert-Check

    Test for a valid certificate on the host.

    Requires Agent Version 3.5 or higher.

    Domain-Verification

    Test for the domain joined by the host.

    Note: This scan has been deprecated. Please use "Domain-Check" instead.

    Domain-Check

    Replaces the "Domain-Verification" scan. Tests for the domain joined by the host. Scan is not Windows OS specific (Windows XP, Windows 7, etc). For additional details, see "Domain verification/Domain check" below.

    File

    Test for the existence and version of a specific file. If the file exists and is an executable the program can be forced to run.

    HotFixes

    Test for the existence of specific HotFixes for the specified Operating systems.

    Processes

    Test for the existence of a specific process name for the indicated Windows operating system.

    Prohibited - Domain-Verification

    Test for the domain joined by the host.

    Requires Agent Version 2.2.2 or higher. Using a lower version of the agent causes all hosts to pass the scan regardless of the domain returned.

    Prohibited-Processes

    Test for the existence of a specific prohibited process for the indicated Windows operating system(s).

    Registry-Keys

    Test for a specific registry key and its associated data.

    Registry-Version

    Test for a specific program and its version. The program can be required for specific versions of Windows.

    Service

    Test the state of a service running on the operating system.

    Requires Agent Version 3.5 or higher.

  8. Enter the Name for the custom scan.
  9. Enter the information for the custom scan.
  10. Click OK.
  11. The name of the custom scan displays in the Custom Scans section for each scan. You can select the custom scan to be part of the creation or modification of scan parameters.

Windows Custom Scan

Windows Custom Scan

The custom scans feature allows you to search host computers for very specific information. Custom scans must be created separately for different operating systems. Within each operating system, there are different types of scans that can be created. Refer to Add A Windows Custom Scan below for a list of scan types and general instructions on adding scans. Refer to the instructions for each scan type for field level information. You can modify or delete the scans at any time. When a scan is modified, it affects any existing scan that use that custom scan.

Add a custom scan
  1. Click Policy & Objects.
  2. Expand Endpoint Compliance.
  3. Click the Scans option to select it.
  4. Click Custom Scans.
  5. Select Add.
  6. Select Windows from the Operating System drop-down list.
  7. Select the type of scan desired. Each scan type has a special set of fields that are specific to that type. Use the table below for settings.

    Type

    Description

    Cert-Check

    Test for a valid certificate on the host.

    Requires Agent Version 3.5 or higher.

    Domain-Verification

    Test for the domain joined by the host.

    Note: This scan has been deprecated. Please use "Domain-Check" instead.

    Domain-Check

    Replaces the "Domain-Verification" scan. Tests for the domain joined by the host. Scan is not Windows OS specific (Windows XP, Windows 7, etc). For additional details, see "Domain verification/Domain check" below.

    File

    Test for the existence and version of a specific file. If the file exists and is an executable the program can be forced to run.

    HotFixes

    Test for the existence of specific HotFixes for the specified Operating systems.

    Processes

    Test for the existence of a specific process name for the indicated Windows operating system.

    Prohibited - Domain-Verification

    Test for the domain joined by the host.

    Requires Agent Version 2.2.2 or higher. Using a lower version of the agent causes all hosts to pass the scan regardless of the domain returned.

    Prohibited-Processes

    Test for the existence of a specific prohibited process for the indicated Windows operating system(s).

    Registry-Keys

    Test for a specific registry key and its associated data.

    Registry-Version

    Test for a specific program and its version. The program can be required for specific versions of Windows.

    Service

    Test the state of a service running on the operating system.

    Requires Agent Version 3.5 or higher.

  8. Enter the Name for the custom scan.
  9. Enter the information for the custom scan.
  10. Click OK.
  11. The name of the custom scan displays in the Custom Scans section for each scan. You can select the custom scan to be part of the creation or modification of scan parameters.