<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Find computers with specific registry key in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562088#M5364</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/248369"&gt;@Piotr_Kowalczyk&lt;/a&gt;&amp;nbsp;you don't need to connect to each computer!&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The script can be run from Incident Response -&amp;gt; Action Center -&amp;gt; Agent Script Library, then look for the script and select Run.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1697551392520.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54473i8D700B2F9099D41D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_0-1697551392520.png" alt="jmazzeo_0-1697551392520.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Then set the registry key.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_1-1697551505426.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54474iD536DE3DDB98A3C0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_1-1697551505426.png" alt="jmazzeo_1-1697551505426.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;And define the target, can be many endpoints at the same time. You only need to select the right filter, can be wildcard like when you assign a profile with the policy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_2-1697551606433.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54475i0FC4C34360EED943/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_2-1697551606433.png" alt="jmazzeo_2-1697551606433.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;(this example is my test VM, based in my prefix "JM")&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Click NEXT, review the settings and click "Run".&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You can see the result in the Action Center - All Actions with right-click -&amp;gt; Additional Data.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_3-1697551835858.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54476i2AE890B892F4AE66/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_3-1697551835858.png" alt="jmazzeo_3-1697551835858.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2023 14:10:50 GMT</pubDate>
    <dc:creator>jmazzeo</dc:creator>
    <dc:date>2023-10-17T14:10:50Z</dc:date>
    <item>
      <title>Find computers with specific registry key</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562057#M5357</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is it possible to find computers which have specific registry key set to particular value using Cortex XDR? I'm not looking for registry modification just for existence. If so, could you tell me how to do this please?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 10:44:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562057#M5357</guid>
      <dc:creator>Piotr_Kowalczyk</dc:creator>
      <dc:date>2023-10-17T10:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Find computers with specific registry key</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562082#M5362</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/248369"&gt;@Piotr_Kowalczyk&lt;/a&gt;&amp;nbsp;, thanks for using the Live Community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Cortex XDR Console comes with a script to check the value of a registry entry:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1697550664646.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54472iDE5A142CE7FA7EB4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_0-1697550664646.png" alt="jmazzeo_0-1697550664646.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You set the path, and this will return the value, and type.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you need to receive a "Exists/Non-exists" return answer from a particular key and the value, then a custom script will be the approach to solve it.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 13:53:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562082#M5362</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2023-10-17T13:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Find computers with specific registry key</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562083#M5363</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My understanding is that this will require to connect with console to particular machine? If so, unfortunately this is not solution which I'm looking for as I need to find all computers (perhaps a few hundreds) which have particular registry value.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 14:00:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562083#M5363</guid>
      <dc:creator>Piotr_Kowalczyk</dc:creator>
      <dc:date>2023-10-17T14:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: Find computers with specific registry key</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562088#M5364</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/248369"&gt;@Piotr_Kowalczyk&lt;/a&gt;&amp;nbsp;you don't need to connect to each computer!&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The script can be run from Incident Response -&amp;gt; Action Center -&amp;gt; Agent Script Library, then look for the script and select Run.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1697551392520.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54473i8D700B2F9099D41D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_0-1697551392520.png" alt="jmazzeo_0-1697551392520.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Then set the registry key.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_1-1697551505426.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54474iD536DE3DDB98A3C0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_1-1697551505426.png" alt="jmazzeo_1-1697551505426.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;And define the target, can be many endpoints at the same time. You only need to select the right filter, can be wildcard like when you assign a profile with the policy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_2-1697551606433.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54475i0FC4C34360EED943/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_2-1697551606433.png" alt="jmazzeo_2-1697551606433.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;(this example is my test VM, based in my prefix "JM")&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Click NEXT, review the settings and click "Run".&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You can see the result in the Action Center - All Actions with right-click -&amp;gt; Additional Data.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_3-1697551835858.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54476i2AE890B892F4AE66/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jmazzeo_3-1697551835858.png" alt="jmazzeo_3-1697551835858.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 14:10:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562088#M5364</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2023-10-17T14:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Find computers with specific registry key</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562093#M5365</link>
      <description>&lt;P&gt;This is exactly what I was looking for! Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 14:45:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/find-computers-with-specific-registry-key/m-p/562093#M5365</guid>
      <dc:creator>Piotr_Kowalczyk</dc:creator>
      <dc:date>2023-10-17T14:45:47Z</dc:date>
    </item>
  </channel>
</rss>

