<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Compliance blade to check Windows registry for Windows Firewall rules in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152643#M5859</link>
    <description>&lt;P&gt;&lt;SPAN&gt;It's Harmony Endpoint managed via the cloud&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Jul 2022 23:06:04 GMT</pubDate>
    <dc:creator>Luiz_</dc:creator>
    <dc:date>2022-07-10T23:06:04Z</dc:date>
    <item>
      <title>Using Compliance blade to check Windows registry for Windows Firewall rules</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152515#M5851</link>
      <description>&lt;P&gt;Hi there checkmates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to create a Compliance rule to check if a specific Windows Defender Firewall rule is present on the user's laptop.&lt;/P&gt;&lt;P&gt;The registry folder where the rules are located is&amp;nbsp;&lt;STRONG&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;The value of each registry is where we look for a certain string to check if the rule we want to check is there, it looks like: v2.30|Action=Allow|Active=TRUE|Dir=Out|&lt;STRONG&gt;Name=Microsoft Solitaire Collection&lt;/STRONG&gt;|Desc=Microsoft Solitaire Collection|LUOwn=S-1-5-21-1918626456-2443561179-3960203745-1002|AppPkgId=S-1-15-2-1985198343-3186790915-4047221937-1969271670-3792558349-1325541827-400269725|EmbedCtxt=Microsoft Solitaire Collection|Platform=2:6:2|Platform2=GTEQ|&lt;/P&gt;&lt;P&gt;The challenge is: the 'name' for each registry is randomized, a value like "{0E69F20E-9517-4D89-A9AB-603E27C8891F}". We can't find a way to check all registries because of that, we would need to use wildcard to do that and we aren't able to do that according to our tests.&lt;/P&gt;&lt;P&gt;Screenshot is attached with the configuration, where we would use * on the "Registry value name" field.&lt;/P&gt;&lt;P&gt;We have an open case with TAC for almost two weeks trying to get this answer but it doesn't go anywhere.&lt;/P&gt;&lt;P&gt;Any ideas? Thanks a lot.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 14:35:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152515#M5851</guid>
      <dc:creator>Luiz_</dc:creator>
      <dc:date>2022-07-07T14:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Using Compliance blade to check Windows registry for Windows Firewall rules</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152640#M5858</link>
      <description>&lt;P&gt;Is this with Harmony Connect or Harmony Endpoint managed via the cloud?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2022 22:10:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152640#M5858</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-10T22:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Using Compliance blade to check Windows registry for Windows Firewall rules</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152643#M5859</link>
      <description>&lt;P&gt;&lt;SPAN&gt;It's Harmony Endpoint managed via the cloud&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2022 23:06:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152643#M5859</guid>
      <dc:creator>Luiz_</dc:creator>
      <dc:date>2022-07-10T23:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Using Compliance blade to check Windows registry for Windows Firewall rules</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152793#M5888</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/35245"&gt;@jcortez&lt;/a&gt;&amp;nbsp;can you think of a better way to do what's trying to be done here?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 12:53:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152793#M5888</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-12T12:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Using Compliance blade to check Windows registry for Windows Firewall rules</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152819#M5890</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/31499"&gt;@Luiz_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is a very good question. Due to the fact that the Registry Key values a randomized it would be very difficult to achieve this. I honestly cannot think of a good workaround.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me have some of our internal resources take a look at this and I will reply back.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 16:15:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152819#M5890</guid>
      <dc:creator>jcortez</dc:creator>
      <dc:date>2022-07-12T16:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Using Compliance blade to check Windows registry for Windows Firewall rules</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152840#M5895</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/31499"&gt;@Luiz_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After speaking with our internal resources the only workaround that could work is creating a wildcard test in a script and using our Compliance Blade to run the script periodically.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 23:28:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152840#M5895</guid>
      <dc:creator>jcortez</dc:creator>
      <dc:date>2022-07-12T23:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Using Compliance blade to check Windows registry for Windows Firewall rules</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152912#M5896</link>
      <description>&lt;P&gt;Very good idea! Thanks a lot!&lt;/P&gt;&lt;P&gt;We're going to try this way.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 16:32:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Using-Compliance-blade-to-check-Windows-registry-for-Windows/m-p/152912#M5896</guid>
      <dc:creator>Luiz_</dc:creator>
      <dc:date>2022-07-13T16:32:33Z</dc:date>
    </item>
  </channel>
</rss>

