Notes
Values
Section
Creates a hard link. See Note 3.
unixfile:link
Creates a directory.
unixfile:mkdir
Opens a file in read only mode.
unixfile:read
Renames a file. See Note 4.
unixfile:rename
Removes a directory.
unixfile:rmdir
Creates a symbolic link.
unixfile:symlink
Deletes a file from a directory or deletes a
directory.
unixfile:unlink
Opens a file in read/write mode.
unixfile:write
Linux only. Changes the permissions
and
ownership of the directory or file.
unixfile:setattr
Creates a node.
unixfile:mknod
Changes the file attributes. Monitored attributes
are “Read-only”, “Hidden”, “Archive” and
“System”.
unixfile:access
Solaris Only. File name has 512 consecutive '/'.
unixfile:foolaccess
Solaris Only. Displays or sets scheduling
parameters.
unixfile:priocntl
Note 1
Relevant directives per section:
New Permission
File Permission
Source
File
Directive
X
X
chdir
X
X
X
chmod
X
chown
X
X
X
create
X
link
X
mkdir
X
read
X
X
rename
X
rmdir
X
setattr
X
X
X
symlink
X
unlink
X
write
Note 2
The value of the sections file permissions and new permissions corresponds to the Access
Control List (acl). These can have values of “SUID” or “SGID” only.
Appendix A — Writing Custom Signatures and Exceptions
Non-Windows custom signatures
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
128