How does opswat and hip checks work? When it really comes down to it, how the heck is the GP agent looking at the windows operating system to see if something is installed and real time protection turned on?
Is the GP agent simply checking the registry against a known"framework" that opswat is defining as "known"? Like if "x" is installed on windows, this registry key will be set to "z"? And if "x" is running real-time protection, this registry key will be set to "y"? So the GP agent looks to see if both z and y are set I the registry, and then the HIP check matches on this? I know that opswat is a framework but how is that actually implemented on a "check" level on the windows OS?
About OPSWAT
OPSWAT protects critical infrastructure. We assume that any file or device entering, traversing, or leaving an enterprise could be a risk. To do this, we provide cyberthreat platforms that not only detect threats, they prevent them. Our platforms deliver a truly secure process for transferring files and devices to and from critical networks. OPSWAT provides this process to over 1,500 customers worldwide. For more information on OPSWAT, visit www.opswat.com and follow us on LinkedIn, Twitter, Facebook, and YouTube.