{"id":17262,"date":"2023-06-27T11:39:01","date_gmt":"2023-06-27T09:39:01","guid":{"rendered":"https:\/\/www.boc.de\/watchguard-info-portal\/?p=17262"},"modified":"2025-05-07T13:43:24","modified_gmt":"2025-05-07T11:43:24","slug":"howto-sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode","status":"publish","type":"post","link":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/2023\/06\/howto-sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode\/","title":{"rendered":"HOWTO: Sind tats\u00e4chlich alle WatchGuard Endpoints im Lock-Mode?"},"content":{"rendered":"<p>Gilt f\u00fcr WatchGuard EPDR, EDR sowie die ehemalige Panda Welt (AD360 &amp; Co.).<\/p>\n<p>Der folgende Artikel beschreibt das Auslesen des erweiterten Schutzmodus auf Basis eines definierten Filters.<\/p>\n<p><strong>Ziel:<\/strong> Damit Sie gegen Angriffsszenarien wie z. B. Hafnium, Log4j, 3CX Supply Chain Attack, Ransomware oder auch zuk\u00fcnftige Angriffe gesch\u00fctzt sind, m\u00fcssen sich alle Endger\u00e4te im sogenannten <strong>Lock-Mode (Windows Only)<\/strong> befinden.<\/p>\n<p><strong>Vorteil der Filterabfrage:<\/strong> S\u00e4mtliche Einstellungen werden <u>direkt<\/u> vom WatchGuard Endpoint Agent ausgelesen, somit werden Fehlfunktionen sowie Fehlkonfigurationen ausgeschlossen.<!--more--><\/p>\n<h3>Vorgehen<\/h3>\n<ol>\n<li>&#8220;Computer&#8221; -&gt; &#8220;My Filters&#8221; (manuell erstellter Ordner) -&gt; &#8220;Filter hinzuf\u00fcgen&#8221; anklicken.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17264 alignnone\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-1.jpg\" alt=\"\" width=\"1333\" height=\"1038\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-1.jpg 1333w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-1-300x234.jpg 300w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-1-1024x797.jpg 1024w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-1-768x598.jpg 768w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-1-800x623.jpg 800w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-1-1200x934.jpg 1200w\" sizes=\"(max-width: 1333px) 100vw, 1333px\" \/><\/li>\n<li>Filter &#8220;Kein Lock-Mode\u201c mit folgenden Parametern erstellen.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17265 alignnone\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-2.jpg\" alt=\"\" width=\"897\" height=\"448\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-2.jpg 897w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-2-300x150.jpg 300w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-2-768x384.jpg 768w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-2-800x400.jpg 800w\" sizes=\"(max-width: 897px) 100vw, 897px\" \/><\/li>\n<\/ol>\n<h5><strong>Unser Tipp:<\/strong><\/h5>\n<p>Dies l\u00e4sst sich ganz einfach via den &#8220;geplanten Berichten&#8221; wie folgt \u00fcberwachen.<\/p>\n<ol>\n<li>&#8220;Status&#8221; -&gt; &#8220;Geplante Berichte&#8221; -&gt; &#8220;Geplanter Bericht hinzuf\u00fcgen&#8221; anklicken.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17267 alignnone\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-3.jpg\" alt=\"\" width=\"1011\" height=\"729\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-3.jpg 1011w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-3-300x216.jpg 300w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-3-768x554.jpg 768w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-3-800x577.jpg 800w\" sizes=\"(max-width: 1011px) 100vw, 1011px\" \/><\/li>\n<li>Beim &#8220;Berichtstyp&#8221; den zuvor erstellen Filter &#8220;Kein Lock-Mode&#8221; ausw\u00e4hlen.<br \/>\nName, Zeitplan\/Uhrzeit usw. nach Belieben anpassen.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17268 alignnone\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-4.jpg\" alt=\"\" width=\"599\" height=\"720\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-4.jpg 599w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2023\/06\/sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode-4-250x300.jpg 250w\" sizes=\"(max-width: 599px) 100vw, 599px\" \/><\/li>\n<\/ol>\n<h3>Weitere Informationen<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-US\/Content\/en-US\/Endpoint-Security\/manage-settings\/windows-operating-modes.html?tocpath=Endpoint%20Security%7CManage%20Settings%7CSecurity%20Settings%7CWorkstation%20and%20Server%20Security%20Settings%7CAdvanced%20Protection%7C_____1\" target=\"_blank\" rel=\"noopener noreferrer\">Advanced Protection \u2013 Operating Modes (Windows computers)<\/a> (WatchGuard Help Center)<\/li>\n<li><a style=\"font-size: inherit; background-color: #ffffff;\" href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-US\/Content\/en-US\/Endpoint-Security\/manage-devices\/filter-devices.html?tocpath=Endpoint%20Security%7CManage%20Computers%20and%20Devices%7CFilter%20Computers%20and%20Devices%7C_____0\" target=\"_blank\" rel=\"noopener noreferrer\">Filter Computers and Devices<\/a> (WatchGuard Help Center)<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Gilt f\u00fcr WatchGuard EPDR, EDR sowie die ehemalige Panda Welt (AD360 &amp; Co.). Der folgende Artikel beschreibt das Auslesen des erweiterten Schutzmodus auf Basis eines definierten Filters. Ziel: Damit Sie gegen Angriffsszenarien wie z. B. Hafnium, Log4j, 3CX Supply Chain Attack, Ransomware oder auch zuk\u00fcnftige Angriffe gesch\u00fctzt sind, m\u00fcssen sich alle Endger\u00e4te im sogenannten Lock-Mode (Windows Only) befinden. Vorteil der Filterabfrage: S\u00e4mtliche Einstellungen werden direkt &hellip; <a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/2023\/06\/howto-sind-tatsaechlich-alle-watchguard-endpoints-im-lock-mode\/\" class=\"more-link\">Weiterlesen <span class=\"screen-reader-text\">HOWTO: Sind tats\u00e4chlich alle WatchGuard Endpoints im Lock-Mode?<\/span> <span class=\"meta-nav\">&raquo;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[362],"tags":[940,676,678,839,737,939,1265,803,1264,453,1047],"class_list":["post-17262","post","type-post","status-publish","format-standard","hentry","category-howto","tag-3cx-supply-chain-attack","tag-ad360","tag-edr","tag-epdr","tag-hafnium","tag-lock-mode","tag-lock-modus","tag-log4j","tag-modus","tag-ransomware","tag-watchguard-endpoint"],"_links":{"self":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/17262"}],"collection":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/comments?post=17262"}],"version-history":[{"count":7,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/17262\/revisions"}],"predecessor-version":[{"id":27003,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/17262\/revisions\/27003"}],"wp:attachment":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/media?parent=17262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/categories?post=17262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/tags?post=17262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}