McAfee HISCDE-AB-IA Product Guide - Page 121

Note 1, Advanced Details

Page 121 highlights

Appendix A - Writing Custom Signatures and Exceptions Windows custom signatures Section Values services:stop services:pause services:continue services:startup services:profile_enable services:profile_disable services:logon Notes Stops a service. Pauses a service. Continues a service after a pause. Modifies the startup mode of a service. Enables a hardware profile. Disables a hardware profile. Modifies the logon information of a service. Note 1 The section service must contain the name of the service of the corresponding registry key under HKLM_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\. The section display_names must contain the display name of the service, the name shown in the Services manager, which is found in registry value HKLM_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\\ . Advanced Details Some or all of the following parameters appear in the Advanced Details tab of security events for the class Services. The values of these parameters can help you understand why a signature is triggered. GUI name display names services params old startup new startup logon Explanation Possible values Name of the Windows service displayed in the Services manager. System name of the Windows service in HKLM\CurrentControlSet\Services\. This may be different from the name displayed in the Services manager. Only applicable for starting a service: parameters passed to the service upon activation. Only applicable for creating or Boot, System, Automatic, Manual, Disabled changing the startup mode of a service: indicates the startup mode before it was changed or attempted to be changed. Only applicable for changing the Boot, System, Automatic, Manual, Disabled startup mode of a service: indicates the startup mode that a service has after it was changed, or that it would have if the change went through. Only applicable for changes in the logon mode of a service: logon information (system or user account)used by the service. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 121

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Notes
Values
Section
Stops a service.
services:stop
Pauses a service.
services:pause
Continues a service after a pause.
services:continue
Modifies the startup mode of a service.
services:startup
Enables a hardware profile.
services:profile_enable
Disables a hardware profile.
services:profile_disable
Modifies the logon information of a service.
services:logon
Note 1
The section service must contain the name of the service of the corresponding registry key
under HKLM_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.
The section display_names must contain the display name of the service, the name shown in
the Services manager, which is found in registry value
HKLM_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<name-of-service>\ .
Advanced Details
Some or all of the following parameters appear in the Advanced Details tab of security events
for the class Services. The values of these parameters can help you understand why a signature
is triggered.
Possible values
Explanation
GUI name
Name of the Windows service
displayed in the Services
manager.
display names
System name of the Windows
service in
services
HKLM\CurrentControlSet\Services\.
This may be different from the
name displayed in the Services
manager.
Only applicable for starting a
service: parameters passed to
the service upon activation.
params
Boot, System, Automatic, Manual, Disabled
Only applicable for creating or
changing the startup mode of a
old startup
service: indicates the startup
mode before it was changed or
attempted to be changed.
Boot, System, Automatic, Manual, Disabled
Only applicable for changing the
startup mode of a service:
new startup
indicates the startup mode that
a service has after it was
changed, or that it would have
if the change went through.
Only applicable for changes in
the logon mode of a service:
logon
logon information (system or
user account)used by the
service.
Appendix A — Writing Custom Signatures and Exceptions
Windows custom signatures
121
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5