McAfee HISCDE-AB-IA - Host Intrusion Prevention Product Manual page 14

Product guide for use with epolicy orchestrator 4.5
Table of Contents

Advertisement

Managing Your Protection
Information management
Query
have no allow/block action. IPS Catalog rules and
groups have the leafNodeId filter value set to 0 ,
so to view firewall client rules only, set the
leafNodeId filter value to > 0 .
Host IPS 8.0 Firewall Client Rule Executables
Host IPS 8.0 IPS Client Rules
Host IPS 8.0 IPS Exceptions
Common Host IPS properties
The Host IPS custom queries and some of the other custom queries allow you to include these
Host IPS properties:
• Agent type
14
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
Parameters
Leaf Node ID
Local Services
Log Status
IP Protocol
Match Intrusion
Media Type
Name
Note
Remote Services
Rule ID
Schedule End
Schedule Start
Switch When Expired
Transport Protocol
Fingerprint
Name
Note
Path
Rule ID
Signer Name
Creation Date
Description
Executable Name
Executable Path
Fingerprint
Full Executable Name
Include All Executables
Include All Signatures
Include All Users
Last Modified Date
Local Version
Reaction
Signature ID
Signer Name
Status
User Name
IPS Exception Rule
IPS Rules Policy
• IPS Adaptive Mode Status

Advertisement

Table of Contents
loading

This manual is also suitable for:

Host intrusion prevention 8.0

Table of Contents