McAfee HISCDE-AB-IA - Host Intrusion Prevention Product Manual page 126

Product guide for use with epolicy orchestrator 4.5
Table of Contents

Advertisement

Appendix A — Writing Custom Signatures and Exceptions
Windows custom signatures
Directives
registry:
read
delete
modify
permissions
enumerate
monitor
restore
replace
load
open_existing_key
rename
Class Services
Directives
services:
start
stop
pause
continue
startup
profile_enable
profile_disable
logon
create
delete
Class SQL
Directives
32-bit processes on 32-bit
Windows OS (x32)
sql:
XP
request
x
126
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
32-bit processes on 32-bit
Windows OS (x32)
XP
2K3
V
2K8
7
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
32-bit processes on 32-bit
Windows OS (x32)
XP
2K3
V
2K8
7
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
32-bit processes on 64-bit
Windows OS (x64)
2K3
V
2K8
7
XP
x
x
x
x
32-bit processes on 64-bit
Windows OS (x64)
XP
2K3
V
2K8
7
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
32-bit processes on 64-bit
Windows OS (x64)
XP
2K3
V
2K8
7
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
2K3
V
2K8
7
64-bit processes on 64-bit
Windows OS (x64)
XP
2K3
V
2K8
7
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
64-bit processes on 64-bit
Windows OS (x64)
XP
2K3
V
2K8
7
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
64-bit processes on 64-bit
Windows OS (x64)
XP
2K3
V
2K8
7
x
x
x
x

Advertisement

Table of Contents
loading

This manual is also suitable for:

Host intrusion prevention 8.0

Table of Contents