Notes
Values
Section
Stops a service.
services:stop
Pauses a service.
services:pause
Continues a service after a pause.
services:continue
Modifies the startup mode of a service.
services:startup
Enables a hardware profile.
services:profile_enable
Disables a hardware profile.
services:profile_disable
Modifies the logon information of a service.
services:logon
Note 1
The section service must contain the name of the service of the corresponding registry key
under HKLM_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.
The section display_names must contain the display name of the service, the name shown in
the Services manager, which is found in registry value
HKLM_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<name-of-service>\ .
Advanced Details
Some or all of the following parameters appear in the Advanced Details tab of security events
for the class Services. The values of these parameters can help you understand why a signature
is triggered.
Possible values
Explanation
GUI name
Name of the Windows service
displayed in the Services
manager.
display names
System name of the Windows
service in
services
HKLM\CurrentControlSet\Services\.
This may be different from the
name displayed in the Services
manager.
Only applicable for starting a
service: parameters passed to
the service upon activation.
params
Boot, System, Automatic, Manual, Disabled
Only applicable for creating or
changing the startup mode of a
old startup
service: indicates the startup
mode before it was changed or
attempted to be changed.
Boot, System, Automatic, Manual, Disabled
Only applicable for changing the
startup mode of a service:
new startup
indicates the startup mode that
a service has after it was
changed, or that it would have
if the change went through.
Only applicable for changes in
the logon mode of a service:
logon
logon information (system or
user account)used by the
service.
Appendix A — Writing Custom Signatures and Exceptions
Windows custom signatures
121
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5