Classes And Directives Per Unix Platform - McAfee HISCDE-AB-IA - Host Intrusion Prevention Product Manual

Product guide for use with epolicy orchestrator 4.5
Table of Contents

Advertisement

Appendix A — Writing Custom Signatures and Exceptions
Non-Windows custom signatures
Section

Classes and directives per UNIX platform

A list of the effective classess and directives per non-Windows platform:
Class UNIX_bo
Directives
unixbo:binargs
unixbo:illegal_address
unixbo:exec
unixbo:enrironment
unixbo:binenv
unixbo:libc
Class UNIX_file
Directives
unixfile:chdir
unixfile:chmod
unixfile:chown
unixfile:create
unixfile:link
unixfile:mkdir
unixfile:read
unixfile:rename
unixfile:rmhdir
unixfile:setattr
unixfile:symlink
unixfile:unlink
unixfile:write
unixfile:mknod
unixfile:access
unixfile:foolaccess
unixfile:priocntl
134
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
Values
guid:setregid
RedHat Linux
SuSE Linux
RedHat Linux
SuSE Linux
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
Notes
Sets the real and effective group ID.
Solaris 9
Solaris 10
X
X
X
X
X
X
X
X
X
X
X
X
Solaris 9
Solaris 10
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X
X

Advertisement

Table of Contents
loading

This manual is also suitable for:

Host intrusion prevention 8.0

Table of Contents