McAfee HISCDE-AB-IA Product Guide - Page 128

Note 1, Control List acl. These can have values of SUID or SGID only.

Page 128 highlights

Appendix A - Writing Custom Signatures and Exceptions Non-Windows custom signatures Section Values unixfile:link unixfile:mkdir unixfile:read unixfile:rename unixfile:rmdir unixfile:symlink unixfile:unlink unixfile:write unixfile:setattr unixfile:mknod unixfile:access unixfile:foolaccess unixfile:priocntl Notes Creates a hard link. See Note 3. Creates a directory. Opens a file in read only mode. Renames a file. See Note 4. Removes a directory. Creates a symbolic link. Deletes a file from a directory or deletes a directory. Opens a file in read/write mode. Linux only. Changes the permissions and ownership of the directory or file. Creates a node. Changes the file attributes. Monitored attributes are "Read-only", "Hidden", "Archive" and "System". Solaris Only. File name has 512 consecutive '/'. Solaris Only. Displays or sets scheduling parameters. Note 1 Relevant directives per section: Directive chdir chmod chown create link mkdir read rename rmdir setattr symlink unlink write File Source X X X X X X X X X X X X X X X File Permission X X New Permission X X X X Note 2 The value of the sections file permissions and new permissions corresponds to the Access Control List (acl). These can have values of "SUID" or "SGID" only. 128 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Notes
Values
Section
Creates a hard link. See Note 3.
unixfile:link
Creates a directory.
unixfile:mkdir
Opens a file in read only mode.
unixfile:read
Renames a file. See Note 4.
unixfile:rename
Removes a directory.
unixfile:rmdir
Creates a symbolic link.
unixfile:symlink
Deletes a file from a directory or deletes a
directory.
unixfile:unlink
Opens a file in read/write mode.
unixfile:write
Linux only
. Changes the permissions
and
ownership of the directory or file.
unixfile:setattr
Creates a node.
unixfile:mknod
Changes the file attributes. Monitored attributes
are “Read-only”, “Hidden”, “Archive” and
“System”.
unixfile:access
Solaris Only
. File name has 512 consecutive '/'.
unixfile:foolaccess
Solaris Only
. Displays or sets scheduling
parameters.
unixfile:priocntl
Note 1
Relevant directives per section:
New Permission
File Permission
Source
File
Directive
X
X
chdir
X
X
X
chmod
X
chown
X
X
X
create
X
link
X
mkdir
X
read
X
X
rename
X
rmdir
X
setattr
X
X
X
symlink
X
unlink
X
write
Note 2
The value of the sections file permissions and new permissions corresponds to the Access
Control List (acl). These can have values of “SUID” or “SGID” only.
Appendix A — Writing Custom Signatures and Exceptions
Non-Windows custom signatures
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
128