Device Posture Rule Input Args
Constructors
Properties
The number of active threats from SentinelOne.
The UUID of a Cloudflare managed certificate.
Specific volume(s) to check for encryption.
Confirm the certificate was not imported from another device.
The workspace one or intune device compliance status. compliant
and noncompliant
are values supported by both providers. unknown
, conflict
, error
, ingraceperiod
values are only supported by intune. Available values: compliant
, noncompliant
, unknown
, conflict
, error
, ingraceperiod
.
The workspace one or intune connection id.
The count comparison operator for kolide. Available values: >
, >=
, <
, <=
, ==
.
The time a device last seen in Tanium. Must be in the format 1h
or 30m
. Valid units are d
, h
and m
.
List of values indicating purposes for which the certificate public key can be used. Available values: clientAuth
, emailProtection
.
The number of issues for kolide.
List of operating system locations to check for a client certificate..
The network status from SentinelOne. Available values: connected
, disconnected
, disconnecting
, connecting
.
The current operational state of a SentinelOne Agent. Available values: na
, partially_disabled
, auto_fully_disabled
, fully_disabled
, auto_partially_disabled
, disabled_error
, db_corruption
.
The operating system excluding version information.
The operating system version excluding OS name information or release name.
Extra version value following the operating system semantic version.
True if all drives must be encrypted.
Sensor signal score from Crowdstrike. Value must be between 1 and 100.
The thumbprint of the file certificate.
The total score from Tanium.
The version comparison operator for Crowdstrike. Available values: >
, >=
, <
, <=
, ==
.