X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fmcafee_av_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fmcafee_av_rules.xml;h=d3b2aab721b9fd0a6f1e8297a487aba85ba6c874;hp=0000000000000000000000000000000000000000;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b
diff --git a/debian/ossec-hids/var/ossec/rules/mcafee_av_rules.xml b/debian/ossec-hids/var/ossec/rules/mcafee_av_rules.xml
new file mode 100644
index 0000000..d3b2aab
--- /dev/null
+++ b/debian/ossec-hids/var/ossec/rules/mcafee_av_rules.xml
@@ -0,0 +1,125 @@
+
+
+^259$|^100$|^1000$|^1001$|^1002$|^1003$|^1004$|^1005$|^1006$|^1007$|^1008$|^5003$|^5005$|^5008$|^5010$|^5011$|^5019$|^5020$|^5021$|^5022$|^5030$|^5031$|^5032$|^5033$|^5034$|^5035$|^5046$|^5047$|^5048$|^5049$|^5051$|^5054$|^5057$|^5059$|^5060$|^5063$|^5063$
+^258$|^5001$|^5028$|^5036$|^5037$|^5038$|^5039$|^5040$|^5041$|^5053$|^5056$|^5061$|^5062$|^5065$
+^257$|^5000$|^5026$|^5052$|^5055$
+quarantined|moved to quarantine|file was deleted|deleted successfully|has been deleted|message deleted|deleted after|cleaned|successfully deleted
+The file \.+ contain|infected with|User defined detection|scan found|error attempting to clean
+10
+
+
+
+ 18101,18102,18103
+ windows
+ ^McLogEvent
+ Grouping of McAfee Windows AV rules.
+
+
+
+ 7500
+ $MCAFEE_INFO
+ McAfee Windows AV informational event.
+
+
+
+ 7500
+ $MCAFEE_WARN
+ McAfee Windows AV warning event.
+
+
+
+ 7500
+ $MCAFEE_ERROR
+ McAfee Windows AV error event.
+
+
+
+ 7500
+ $MCAFEE_VIRUS
+ virus
+ McAfee Windows AV - Virus detected and not removed.
+
+
+
+ 7504
+ $MCAFEE_VIRUS_OK
+ virus
+ McAfee Windows AV - Virus detected and properly removed.
+
+
+
+ 7504
+ Will be deleted
+ virus
+ McAfee Windows AV - Virus detected and file will be deleted.
+
+
+
+ 7500
+ scan started|scan stopped
+ McAfee Windows AV - Scan started or stopped.
+
+
+
+ 7501
+ ^257
+ completed. No detections
+ McAfee Windows AV - Scan completed with no viruses found.
+
+
+
+ 7500
+ scan was cancelled |has taken too long
+ McAfee Windows AV - Virus scan cancelled.
+
+
+
+ 7500
+ scan was canceled because
+ McAfee Windows AV - Virus scan cancelled due to shutdown.
+
+
+
+ 7500
+ update was successful
+ McAfee Windows AV - Virus program or DAT update succeeded.
+
+
+
+ 7500
+ update failed
+ McAfee Windows AV - Virus program or DAT update failed.
+
+
+
+ 7500
+ update was cancelled
+ McAfee Windows AV - Virus program or DAT update cancelled.
+
+
+
+ 7505
+ contains the EICAR test file
+ alert_by_email
+ McAfee Windows AV - EICAR test file detected.
+
+
+
+
+
+ 7502
+ Multiple McAfee AV warning events.
+
+
+
+