Notes
Values
Section
Example: sa
Name of the user if SQL
authentication was used, and
db_user_name
"Trusted User" if Windows
authentication is used.
This should match a stored procedure name. A
stored procedure is identified by a supplied list of
Stored procedure name.
sp_name
procedure names that is included for every SQL
agent release (currently SPList.txt in the Agent
directory).
Contains the length of the
parameter in number of
characters.
sp_param_char_len_one...
Contains the value of the
parameter.
sp_param_one...
Contains the length of the
parameter in number of bytes.
sp_param_orign_len-one...
This value is set to 1 if the query
includes a single line comment
"-" containing a single quote.
sql_line_comment
This contains the full SQL query
exactly as it was received
sql_original_query
(including strings and
whitespaces).
This is the SQL query string with
string values, whitespaces, and
sql_query
everything behind the comments
stripped out.
This is always be set to 0 for non-SQL users.
This is set to 1 if the password
is NULL and 0 otherwise.
sql_user_password
On MSSQL 2005/2008, this is
hard coded to: Shared memory
(LPC).
transport
For incoming SQL requests
sql:request.
directives
Classes and directives per Windows platform
A list of the effective classess and directives per Windows platform:
• Windows XP, SP2, SP3, 32- and 64-bit (XP)
• Windows 2003, R2, R2 SP2, 32- and 64-bit (2K3)
• Windows Vista, 32- and 64-bit (V)
• Windows 2008 R2, (32- and 64-bit (2K8)
• Windows 7, 32- and 64-bit (7)
Appendix A — Writing Custom Signatures and Exceptions
Windows custom signatures
123
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5