Product Version: 6.5.0.0
Overview
The Posture Anomaly (PA) tool in Saner CVEM enables users to perform detailed endpoint assessments through a variety of detection queries. These queries can be customized to gather specific system information, such as disk space usage, antivirus status, and firewall configuration. This article provides step-by-step instructions to create and execute custom detection queries in the Posture Anomaly tool to retrieve these system details.
Steps to Retrieve Disk Space, Antivirus, and Firewall Information
1. Accessing the Posture Anomaly Tool
Log in to your Saner CVEM console.
Navigate to the desired Account/Site section.
Select the Posture Anomaly (PA) tool from the left menu.
Once the tool loads, click on Custom Rules.
In the Detection and Response window, ensure the Detection tab is selected.
You can now search and use predefined queries or create your own custom detection rules.
2. Creating Custom Queries
a. Fetching Disk Space Information
In the Detection Queries panel, search for Partitions.
Drag and drop the query into the Action Box.
Click And to build your query.
From the dropdown, select parameters such as:
Disk Name
Disk Type
Total Space
Used Space
Available Space
Select the target devices and click Deploy.
In the Deploy Package popup, provide a Query Name and click Create.
The query will now appear under Custom Detection Rules in the PA module.
Click Run under the Action column to execute the query.
Once devices respond, click Fetch to retrieve results, and then click More to view detailed disk information.
b. Fetching Antivirus Information
Follow the same process as above.
Search for Antivirus Information in the query list.
Drag and drop it into the Action Box.
Update the value to true to detect active antivirus software.
Deploy and execute the query as described in the previous section.
Use the Fetch option to view antivirus details from the target systems.
c. Fetching Firewall Status
Follow the same procedure as above.
Search for Firewall in the query list.
Drag and drop it into the Action Box.
Update the value to enabled to detect active firewall services.
Deploy and execute the query as described earlier.
Once devices respond, fetch and view the results to confirm the firewall status.
Conclusion
By leveraging the Posture Anomaly (PA) tool in Saner CVEM, administrators can quickly create and deploy custom detection queries to retrieve crucial system information such as disk usage, antivirus presence, and firewall status. These insights help in monitoring endpoint health, ensuring security compliance, and maintaining an up-to-date infrastructure overview.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article