Already a NinjaOne customer? Log in to view more guides and the latest updates.

NinjaOne Policies: Conditions: Antivirus Health

Topic

This article provides a description of the antivirus conditions that can be managed under your policies in the NinjaOne console. 

Environment

NinjaOne Endpoint Management

Description

The Antivirus Health condition is triggered if antivirus software is missing, disabled, outdated, or if multiple antivirus software programs are installed, allowing technicians to set up health conditions accordingly. 

This condition is dependent on the accuracy of the Windows Security Center. Some antivirus products may not report accurately or at all. 

A minimum of one checkbox must be selected before the condition can be saved.

CriteriaDescription
Detect Multiple Antivirus InstalledWhen selected, this condition triggers when the Windows Security Center detects more than one antivirus reporting to it. When checked, this condition triggers and returns a list of the detected antiviruses.
Ignore Microsoft Defender AntivirusMicrosoft Defender Antivirus is often installed by default on most new Windows operating systems. When checked, all Microsoft Defender Antivirus related information is dismissed and discounted.
Duration DetectedThis is the amount of time between detection and the condition triggering for any of the sub-conditions.

antivirus health condition.png
Figure 1: Antivirus Health condition configuration modal

Other Antivirus Conditions

Template NameConditionProcess / Service / SourceUp / Down / Event IDsTime / Text
Webroot: Process DownProcessWebroot SecureAnywhere Core Service, Webroot SecureAnywhere Endpoint Protection, WRCoreService, WRSkyClient, WRSVCDown3 Minutes
Webroot: Daemon DownDaemonWSDaemonDown3 Minutes
Sophos: Service DownWindows ServiceSophos Agent, Sophos Anti-Virus, Sophos AutoUpdate Service, Sophos Client Firewall, Sophos Client Firewall Manager, Sophos Device Control Service, Sophos Device Encryption Service, Sophos Endpoint Defense Service, Sophos Patch Agent, Sophos Web Control Service, Sophos Web Intelligence Service, Sophos Web Intelligence Update, Sophos Web Filter Service, Sophos Network Treat Protection, Sophos System Protection Service, Sophos Clean Service, HitmanPo.Alert Service, Sophos Live Query, Sophos Safestore ServiceDown3 Minutes
ESET: Service DownWindows ServiceekmEpfw, ehttpsrv, ekrn, efdeais, efdesrv, EraAgentSvcDown3 Minutes
Windows Defender: Service DownWindows Servicewindefend, mpssvc, MsMpEng, Windows Defender ServiceDown3 Minutes
Trend Micro: Apex One Service DownWindows ServiceCETASvc, Trend Micro Endpoint Basecamp, Trend Micro Web Service Communicator, TmCCSF, tmlisten, ntrtscan, TmWSCSvcDown3 Minutes
Trend Micro: Worry-Free Business Security Service DownWindows ServicePccNTMon, PccNT, TmListen, NTRtScan, TmPfw, TMBMSRVDown3 Minutes
Trend Micro: Service DownDaemoncom.trendmicro.icore.mainDown3 Minutes
Kasperskey: Service DownWindows Servicesoyuz, angaraDown3 Minutes
Broadcom (Symantec) Endpoint Protection: Service DownWindows Servicesnc64, DoScan, Smc, SepMasterService, ccSvcHstDown3 Minutes
Broadcom (Symantec) Endpoint Protection Manager : Service DownWindows ServiceSemSvc, SemLaumchSvcDown3 Minutes
AVG: Service DownWindows ServiceAVG Antivirus, avgIDSAgent, AvgWscReporter, AVG Secure Browser Elevation Service, avg8wd, avgadmsv, avgtcpsvDown3 Minutes
MalwareBytes: Service DownWindows ServiceMBAMService, MBEndpointAgent, MBAMIService, mbMgmtSvc, MsMpSvc, MBAMSchedulerDown3 Minutes
VIPRE: Service DownWindows ServiceVipreNis, SBAMSvc, ViprePPLSvcDown3 Minutes
Panda: Service DownWindows ServiceNanoServiceMain, PandaAgent, pselamsvc, PSUAService, Panda VPN ServiceDown3 Minutes

Additional Resources

Refer to the following resource(s) to learn more about conditions in NinjaOne.

FAQ

Next Steps