Control Registry Keys with GlobalProtect
Do you want to know how to use Palo Alto Networks GlobalProtect to validate registry keys on Windows systems?
Reddit user u/cr0100 had this same challenge. I've configured this a few times before so I was able to help him with his configuration.
In this video I walk through the steps to set up your Host Information Profile (HIP), Security Policy, and GlobalProtect portal to validate "Custom Checks" which include registry keys.
Remember these three steps:
1. Configure your HIP Object(s) and Profile
2. Configure a security policy with your HIP Profile as Source Device
3. Configure the Portal to collect the Registry Key(s) in these 3 place: Portal Data Collection, Agent Config Collection Criteria, and Agent HIP Data Collection
Original Reddit post: https://www.reddit.com/r/paloaltonetworks/comments/1i98n6d/globalprotect_custom_hip_checks_im_going_bonkers/
Knowledgebase article on configuring Custom Checks for Registry Keys: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbKCAS&lang=en_US