





Parameter Name | Description | |
Detection Method | Keyword | Detection condition: Matches specific words and is suitable for detecting explicit word information. |
| Regex | Regular expression: Matches text formats through flexible pattern rules and is suitable for detecting complex patterns such as variants. |
Violation level | | High, medium, and low severity. |
Repair Guide | | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. For remediation guide documents, see Help Center. |
Violation handling | | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |











Parameter | Description |
Software | Select the third-party antivirus software name based on control requirements. |
Check software version. | Enable: If you select Enable, you must set the software version number. Disable: No software version number is required. |
Check virus database version. | Enable: If you select Enable, you must set the virus database version number. Disable: No virus database version number is required. |
Check for latest virus database. | Enable: Set the number of days since the latest virus database detection update based on your management requirements. Disable: No need to configure checking for the latest virus database. |
Violation level | High, medium, and low severity. |
Repair Guide | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. |
Violation handling | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Only alert users about whether they are compliant. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked with the Zero Trust gateway): Force logout of the enterprise account and restrict terminal access to private network resources. |












Parameter Name | Description | |
Required software | Software | Required field. It is only used to display the required software name on the client and is not used as a detection condition. |
| Software download URL | Optional. After you enter the download URL of this software (the official website download URL), if the client detection result is non-compliant, the page will display the software download URL. |
| Registry subkey name | When Registry Subdirectory Name is selected, the corresponding subdirectory name is searched from the registry uninstallation path to determine whether the software is installed. For example, if Edge is entered, the registry uninstall directory is searched. Some software may not write its subdirectory name to the uninstall registry path, which may make detection impossible. In this case, you are advised to use Registry Path for detection. How to find the registry subkey name: 1. Open Registry Editor: Press Win + R to open the Run dialog, type regedit, and then press Enter. 2. Navigate to the target path: In Registry Editor, expand the target path in sequence and view the names of its subkeys. |
| Software version | Optional. After you select Registry Subdirectory Name, the software version number is displayed when you click ![]() Custom software version number. |
| Process name | Optional. After you select Registry Subdirectory Name, the process name is displayed when you click ![]() If a process name is entered, the system detects whether the process is started and prompts that the device is non-compliant if it is not. |
| MD5 (32-bit) | Optional. After you select Registry Subdirectory Name, the MD5 value is displayed when you click ![]() The MD5 value of the software. |
| Registry path | When "Registry path" is selected, you can search the full registry path to determine whether the software is installed. Example: HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Edge. How to find the registry path of a software: 1. Open Registry Editor: Press Win + R to open the Run dialog, type regedit, and then press Enter. 2. Navigate to possible paths: Registry entries for most application software are located in HKEY_LOCAL_MACHINE\\SOFTWARE or HKEY_CURRENT_USER\\Software. 3. You can search by software installation path or company name. For example: HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall: Uninstall information for installed software is stored under this path. HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\App Paths: Executable file paths for certain applications are stored under this path. 4. Search by software name: In Registry Editor, use the Find feature (Ctrl + F) and enter the software name or related keywords to search. |
| Version key name. | Optional. After you select Registry Path, the version key name is displayed when you click ![]() Find the version key name: In Registry Editor, software version information is typically stored in HKEY_LOCAL_MACHINE\\SOFTWARE\\[Software Vendor]\\[Software Name]. Common key names include DisplayVersion, Version, and ProductVersion. |
| Version key value | Optional. After you select a registry path, the version key value is displayed when you click ![]() Find the version key value: You can view it through file properties. Right-click the program file and go to Properties > Details > File version/Product version. |
| Process name | Optional. After you select Registry Path, the process name is displayed when you click ![]() If a process name is entered, the system detects whether the process is started and prompts that the device is non-compliant if it is not. |
| MD5 (32-bit) | Optional. After you select Registry Path, the MD5 value is displayed when you click ![]() The MD5 value of the software. |
| More advanced settings | Precise IP address settings: Supports precise matching by IP address range. The client applies the corresponding policy only within the specified network range. |
Non-compliant Software | Software | Required field. It is only used to display the required software name on the client and is not used as a detection condition. |
| Registry subkey name | When Registry Subdirectory Name is selected, the corresponding subdirectory name is searched from the registry uninstallation path to determine whether the software is installed. For example, if you enter Edge, the registry uninstall directory is searched. Some software may not write its subdirectory name to the uninstall registry path, which may make detection impossible. In this case, you are advised to use Registry Path for detection. How to find the registry subkey name: 1. Open Registry Editor: Press Win + R to open the Run dialog, type regedit, and then press Enter. 2. Navigate to the target path: In Registry Editor, expand the target path in sequence and view the names of its subkeys. |
| Software version | Optional. After you select Registry Subdirectory Name, the software version number is displayed when you click ![]() Custom software version number. |
| Registry path | When "Registry path" is selected, you can search the full registry path to determine whether the software is installed. Example: HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Edge. How to find the registry path of a software: 1. Open Registry Editor: Press Win + R to open the Run dialog, type regedit, and then press Enter. 2. Navigate to possible paths: Registry entries for most application software are located in HKEY_LOCAL_MACHINE\\SOFTWARE or HKEY_CURRENT_USER\\Software. 3. You can search by software installation path or company name. For example: HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall: Uninstall information for installed software is stored under this path. HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\App Paths: Executable file paths for certain applications are stored under this path. 4. Search by software name: In Registry Editor, use the Find feature (Ctrl + F) and enter the software name or related keywords to search. |
| Version key name. | Optional. After you select Registry Path, the version key name is displayed when you click ![]() Find the version key name: In Registry Editor, software version information is typically stored in HKEY_LOCAL_MACHINE\\SOFTWARE\\[Software Vendor]\\[Software Name]. Common key names include DisplayVersion, Version, and ProductVersion. |
| Version key value | Optional. After you select a registry path, the version key value is displayed when you click ![]() Find the version key value: You can view it through file properties. Right-click the program file and go to Properties > Details > File version/Product version. |
| More advanced settings | Precise IP address settings: Supports precise matching by IP address range. The client applies the corresponding policy only within the specified network range. |






Parameter Name | Description | |
Non-compliant process | | Enter the process name. |
Process command line | | Supports detection, identification, and display of AI agents such as OpenClaw and QClaw. Once a corresponding Agent is detected, the system can prompt users through a pop-up/prohibit access to the private network (integrated with the zero trust gateway module). ![]() |
Violation level | | High, medium, and low severity. |
Repair Guide | | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. For remediation guide documents, see Help Center. |
Violation handling | | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |






Parameter Name | Description |
non-compliant service | Enter the service name. |
Violation level | High, medium, and low severity. |
Repair Guide | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. |
Violation handling | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |






Parameter Name | Description |
non-compliant ports | Enter the TCP port. Enter the UDP port. |
Violation level | High, medium, and low severity. |
Repair Guide | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. For remediation guide documents, see Help Center. |
Violation handling | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |










Parameter Name | Description |
Detection domain | Enter the domain name. |
Precise IP settings | All IPs: All IPs within the range will be detected. Local IP address: The IP address used by the terminal to connect to the central console. Egress IP: The IP address used by the terminal to connect to the public network. |
Violation level | High, medium, and low severity. |
Violation handling | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |






Parameter Name | Description |
Detect client version lower than | Enter the minimum client version required for user installation based on your company's control requirements. |
Violation level | High, medium, and low severity. |
Repair Guide | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. For remediation guide documents, see Help Center. |
Violation handling | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |






Parameter Name | Description |
Detect OS version lower than | Dropdown selection: Windows XP, Windows Vista, Windows 7, Windows 8, Windows 10, Windows 11. |
Detect OS minor version lower than | Enter the system version. To view the system version: press Win+R, type cmd and press Enter, then type ver and press Enter. |
Violation level | High, medium, and low severity. |
Repair Guide | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. For remediation guide documents, see Help Center. |
Violation handling | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |













Parameter Name | Description | |
Violating registry | Registry Entry | Required field. Example: Install a WinRAR decompression software. Example of registry entry: HKEY_LOCAL_MACHINE\\SOFTWARE\\WinRAR. |
| Key Name | Required field. Example: exe32. |
| Value Type | Required field. Select from the drop-down list: REG_SZ, REG_DWORD (decimal), REG_MULTI_SZ, REG_EXPAND_SZ, REG_QWORD (decimal). |
| Key-value | Optional. Example: C:\\Program Files\\WinRAR\\WinRAR.exe. |
Violation level | | High, medium, and low severity. |
Repair Guide | | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. For remediation guide documents, see Help Center. |
Violation handling | | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |





Parameter Name | Description | ||
Violation level | | | High, medium, and low severity. |
Remediation method | | One-Click Fix | When non-compliance is detected, the user must manually click one-click repair on the client to complete the fix. |
| | Repair Guide | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. For remediation guide documents, see Help Center. |
Violation handling | | | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |





Parameter Name | Description | ||
Violation level | | | High, medium, and low severity. |
Remediation method | | One-Click Fix | When non-compliance is detected, the user must manually click one-click repair on the client to complete the fix. |
| | Repair Guide | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. For remediation guide documents, see Help Center. |
Violation handling | | | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |





Parameter Name | Description |
Violation level | High, medium, and low severity. |
Repair Guide | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. For remediation guide documents, see Help Center. |
Violation handling | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |



Parameter Name | Description | ||
Violation level | | | High, medium, and low severity. |
Remediation method | | One-Click Fix | When non-compliance is detected, the user must manually click one-click repair on the client to complete the fix. |
| | Repair Guide | Customize the client notification message. You can associate remediation documents to guide users through customized instructions for completing the fix, improving compliance remediation efficiency. For remediation guide documents, see Help Center. |
Violation handling | | | Login prohibited when non-compliant: Non-compliance detection results in forced logout from the enterprise account and a login block. Alert only when non-compliant: Prompt users through a pop-up upon detecting non-compliance. Network disconnected when non-compliant (linked to admission): The terminal cannot connect to the private network when non-compliance is detected. Disable Zero Trust Office when non-compliant (linked to the Zero Trust gateway): Blocks access to private network resources upon detecting non-compliance. |


フィードバック