> Source: [sk182513](https://support.checkpoint.com/results/sk/sk182513)

# sk182513 - How to verify whether the client is E1 or E2

| Property | Value |
|----------|-------|
| Solution ID | sk182513 |
| Date Created | 2024-07-17 |
| Last Modified | 2024-08-09 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, R82.20, R82.10, R82, R81.20 |
| OS | Windows |

## Solution

Introduction
------------

Some versions of Check Point Harmony Endpoint for Windows use the Kaspersky Anti-Malware engine for static file analysis. This is called E1.  

Check Point also offers a version of Harmony Endpoint that does not include the Kaspersky Anti-Malware engine. This is called E2 (the DHS-Compliant version).   

Even if Anti-Malware blade is not installed on a computer, the package used for the HEP installation may include files of Kaspersky Anti-Malware engine.   

How to verify whether the client has files of E1
------------------------------------------------

To verify whether the client is E1, E2, or the package used for Harmony Endpoint installation includes files related to Kaspersky Anti-Malware engine, download and use [**this script**](https://support.checkpoint.com/results/download/134244) (for PowerShell 5.0+).  

The script may return these results:

* If the installed engine is E1, it will exit with: **`E1 engine is installed`**
* If the installed engine is E2, it will exit with: **`E2 engine is installed`** If Anti-Malware blade is not installed, then the script will check the cached MSI of the installed version. This check is mostly related to the static packages used for installation of any set of blades without the AM blade.
* If the cached MSI of the installed version includes files of E1 engine, the script reports it in this format:

  ```
  `E1 files were detected in C:\Windows\Installer\<Filename>.msi of the installed E<version>`.
  ```

  For example, **`E1 files were detected in C:\Windows\Installer\10c97abc.msi of the installed E88.41.1001`.**
* If E1 files were not detected the script will report: **`No E1 files detected`**

**Note:**If E1 is installed or detected, then the exit code of the script will be 1, otherwise the exit code will be 0.  

How to run the script from the client
-------------------------------------

Show / Hide this section  
> The script can be executed on the client using one of the following methods:
>
> * Using Group Policy Objects (GPO)
> * Using Windows PowerShell
> * Using a **Remote Command push** operation from the Harmony Endpoint Administrator Portal.   
>   **Note:** This option is supported only for Harmony Endpoint EPMaaS versions and R81.20 version with latest JHF.
>
> To run the script using **Remote Command** push operation using a Harmony Endpoint Administrator Portal:
>
> 1.
>    1. Login to the Harmony Endpoint Administrator Portal.
>    2. Go to the **Push Operation** view and click **Add**.
>    3. From the **Select Push Operation** dropdown, select **Agent Settings** \> **Remote Command** and click **Next**.
>    4. Select the devices on which you want to perform this push operation.
>       1. If required, click **+** to add the devices and click **Update Selection**.
>    5. Click **Next**.
>    6. Provide a comment for the push operation in the **Comment**field.
>    7. From the **Type** dropdown, select **Unsigned Power Shell**.
>    8. From the list of **User settings** , select **Currently logged-in user**.
>    9. In the **Script** field, click **Upload** and select the script (`CheckAmEngine`) downloaded in the previous section.
>    10. In the **PowerShell command line Arguments** field, enter `ExecutionPolicy ByPass`.
>    11. Click **Finish.**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
