T Techclick ← All lessons
Forescout · eyeSight / eyeControl · Lesson 11 of 13

HPS posture: inspect Windows, then remediate

Priya is classified Laptop / Windows 11. Someone enabled “quarantine if AV is off” the same afternoon. The host was never Manageable. HPS Inspection Engine is how eyeSight reads Windows — it is not a block button.

Updated 2026-08-18·18 min read·L2 primary·Quiz at end

After this page you can

The ticket

Helpdesk: “NAC blocked Priya.” Host Details: Function = Laptop, OS = Windows 11. Windows Manageable Domain is empty. Policy Actions shows a control that never had a property to evaluate. That is not a failed AV check. That is a failed inspect.

Quick interview answer

HPS Inspection Engine (Host Property Scanner) lets eyeSight access Microsoft Windows endpoints: classification, OS/security/services/apps, then optional remediation actions. Access is Remote Inspection (WMI and other domain/host protocols; TCP 445 on Windows 7+) or SecureConnector (small executable on the host, encrypted tunnel to the Appliance on TCP 10003). When access succeeds the host is Manageable. Manageable is not compliant. Docs: About the HPS Inspection Engine; Configure via Tools → Options → Modules → Endpoint → HPS Inspection Engine → Configure.

Hero · inspect before quarantine
Windows laptop inspected by HPS before any quarantine VLAN
If Manageable is empty, do not pretend AV failed.
Lab data · dummy only

Enterprise Manager fs-em 10.10.10.30 · Appliance fs-app1 10.10.10.31 · span/mirror on sw-access-01 · same LAN 10.20.30.0/24 · Priya 10.20.30.80 · printer 10.20.30.60 · OT PLC 10.50.1.10. Not a live customer.

Two inspection paths

Remote InspectionSecureConnector
HowWMI / SMB-RPC from the ApplianceAgent on the endpoint reports in
PortTCP 445 (Win 7+); 139 on olderTCP 10003 to the Appliance
Proof propertyWindows Manageable Domain / LocalWindows Manageable SecureConnector
NeedsReachable host + least-privilege inspect accountStart SecureConnector action + firewall allow
Inspect path is not the control path
Priya 10.20.30.80Windows 11 laptop HPS InspectionWMI or SecureConnector→ Manageable Inspect policyAV / patch / firewall Control laternotify → VLAN

Classification (lesson 4) is what the device is. HPS is whether you can read Windows. Control is a later checkbox.

https://fs-em.techclick-lab.in
Training mock · not live
Asset InventoryPolicyChannelsTools
Tools → Options → Modules → Endpoint

HPS Inspection Engine

HPS Inspection Engine — Running
WMI / SMB-RPC — TCP 445
TCP 10003 to fs-app1 — Off for OT
10.20.30.80 — Windows Manageable Domain = Yes
Official path: Tools → Options → Modules → Endpoint → HPS Inspection Engine → Configure. Training mock.

When SecureConnector

Remote Inspection first for on-net domain PCs that allow WMI. SecureConnector when the laptop is off-net, firewalled, or you need a Start SecureConnector / HTTP install path. Never install SecureConnector on the PLC VLAN. Never use a Domain Admin shared secret as the inspect account — least privilege, logged.

How you prove posture

  1. Side A — module

    Tools → Options → Modules → Endpoint → HPS Inspection Engine. Running. Connectivity test against a host that is allowed to be inspected (docs suggest a DC/LDAP address for the test — not a PLC).

  2. Side B — host properties

    Host Details on 10.20.30.80: Windows Manageable Domain or SecureConnector analogue is true before you read AV/patch. Empty Manageable = stop.

  3. Side C — policy

    Inspect-only: log AV / host firewall / patch window. Notify week. Control (HTTP Notification, quarantine VLAN) only on the manageable Windows group — never on Unknown, never on 10.50.1.0/24.

Four HPS failures

1 · Control before Manageable

Policy fires “AV missing” because the property never resolved. Quote Manageable first.

2 · TCP 445 filtered

Remote Inspection needs 445 (Win 7+). Host firewall or a downstream NGFW silently drops WMI. That is a path ticket, not a “HPS is broken” ticket.

3 · SecureConnector but 10003 closed

Docs: SecureConnector creates an encrypted tunnel to the Appliance on TCP 10003. Enterprise firewalls must allow it. Partial Enforcement also disables HTTP Actions / Virtual Firewall — do not delete the posture policy until you have quoted that mode.

4 · Domain Admin inspect account campus-wide

Blast radius if the Appliance is abused. Dedicated least-privilege account. OT prefixes stay in the exclude list from lesson 3.

How to prove it

Close the ticket only when

1) HPS module Running. 2) Priya shows a Manageable property. 3) Inspect policy hit is logged. 4) No control on Unknown or 10.50.1.10. 5) 445 or 10003 path is written on the ticket if inspect failed.

Traps

WrongRight
Classified Windows = we can read AVRead Windows Manageable * first
Quarantine Unknown because “posture”Unknown is a discovery ticket (lesson 4)
HPS on the PLC VLANPassive only (lesson 9)
HTTP Notification never shownNAC → HTTP Redirection + Partial Enforcement — not “delete HPS”

Knowledge check

Judgment items. One best answer. Reasons send you back to the matching section.

Q1

HPS Inspection Engine’s job?

Correct: b. About the HPS Inspection Engine — access Windows, classify, deep inspect, then optional actions.
Q2

Where do you open HPS configuration in this class?

Correct: a. Official Configure the HPS Inspection Engine path.
Q3

SecureConnector tunnel to the Appliance uses…

Correct: c. HPS plugin requirements — encrypted tunnel on TCP 10003.
Q4

Priya is classified Windows but Manageable is empty. First?

Correct: d. Ticket + Side B.
Q5

Remote Inspection on Windows 7+ needs which port available?

Correct: b. Operational requirements — 445/TCP on Windows 7 and above.
Q6

When is quarantine OK in this design?

Correct: a. Runbook Side C + lesson 4/9.

Forescout class series: Three products · First day · Discovery · Classification · Policy · Enforcement · Switch plugin · eyeExtend · OT / IoT · vs ISE + interview · HPS posture · eyeSegment matrix · RADIUS 802.1X MAB

Sources

Related: Forescout evidence desk · session factory · Cisco ISE series.