- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-17-2023 03:44 AM
Hi,
Is it possible to find computers which have specific registry key set to particular value using Cortex XDR? I'm not looking for registry modification just for existence. If so, could you tell me how to do this please?
10-17-2023 06:53 AM - edited 10-17-2023 06:53 AM
Hi @Piotr_Kowalczyk , thanks for using the Live Community!
The Cortex XDR Console comes with a script to check the value of a registry entry:
You set the path, and this will return the value, and type.
If you need to receive a "Exists/Non-exists" return answer from a particular key and the value, then a custom script will be the approach to solve it.
10-17-2023 07:10 AM
@Piotr_Kowalczyk you don't need to connect to each computer!
(this example is my test VM, based in my prefix "JM")
10-17-2023 06:53 AM - edited 10-17-2023 06:53 AM
Hi @Piotr_Kowalczyk , thanks for using the Live Community!
The Cortex XDR Console comes with a script to check the value of a registry entry:
You set the path, and this will return the value, and type.
If you need to receive a "Exists/Non-exists" return answer from a particular key and the value, then a custom script will be the approach to solve it.
10-17-2023 07:00 AM
Thank you for your reply.
My understanding is that this will require to connect with console to particular machine? If so, unfortunately this is not solution which I'm looking for as I need to find all computers (perhaps a few hundreds) which have particular registry value.
10-17-2023 07:10 AM
@Piotr_Kowalczyk you don't need to connect to each computer!
(this example is my test VM, based in my prefix "JM")
10-17-2023 07:45 AM
This is exactly what I was looking for! Thank you!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!