Verify the Trust Provider

Prev Next

The xAgent compares the digital signature of the Trust Provider (TP) to your configured TP value and generates an alert if they do not match. The "Verify Trust Provider" setting is enabled by default. When enabled, modifying registry entries, with the intent of corrupting the TP, will generate a TAMPER_PROTECTION alert, as described in Wintrust Alerts .

To change the Verify Trust Provider setting on your host endpoints:

Important

The following configuration only applies to Windows xAgent versions 35.31.0 and above.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.

  4. Select the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Verify Trust Provider.

  6. Click Save to save the policy settings.