Notes
Values
Section
time
user_name
Executable (Use this parameter
to distinguish between remote
and local file access. See Note
3.)
One of the required parameters. See Note 1 and
Note 2.
File or folder involved in the
operation
files
One of the required parameters. Used only with
files:rename and files:hardlink. See Note 1 and
Note 2.
Destination files if the operation
involves source and destination
files
dest_file
Allows creation of files class rules specific to drive
types.
drive_type
•
Network — Network file
access
•
Floppy — Floppy drive
access
•
CD — CD or DVD access
•
OtherRemovable — USB or
other removable drive
access
•
OtherFixed — Local hard
disk or other fixed hard disk
access
Creates a file in a directory, or moves file into
another directory.
files:create
directives
Opens the file with read only access.
files:read
Opens the file with read-write access.
files:write
Executes the file (executing a directory means
that this directory will become the current
directory).
files:execute
Deletes the file from a directory, or moves it to
another directory.
files:delete
Renames a file in the same directory. See Note
2.
files:rename
Changes the file attributes. Monitored attributes
include:
files:attribute
•
read-only
•
hidden
•
archive
•
system
Creates a hard link.
files:hardlink
Note 1
If the section files is used, the path to a monitored folder or file can either be the full path or
a wildcard. For example, the following are valid path representations:
files { Include “C:\\test\\abc.txt” }
files { Include “*\\test\\abc.txt” }
Appendix A — Writing Custom Signatures and Exceptions
Windows custom signatures
109
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5