X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fmcafee_av_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fmcafee_av_rules.xml;h=d3b2aab721b9fd0a6f1e8297a487aba85ba6c874;hp=0000000000000000000000000000000000000000;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b diff --git a/debian/ossec-hids/var/ossec/rules/mcafee_av_rules.xml b/debian/ossec-hids/var/ossec/rules/mcafee_av_rules.xml new file mode 100644 index 0000000..d3b2aab --- /dev/null +++ b/debian/ossec-hids/var/ossec/rules/mcafee_av_rules.xml @@ -0,0 +1,125 @@ + + +^259$|^100$|^1000$|^1001$|^1002$|^1003$|^1004$|^1005$|^1006$|^1007$|^1008$|^5003$|^5005$|^5008$|^5010$|^5011$|^5019$|^5020$|^5021$|^5022$|^5030$|^5031$|^5032$|^5033$|^5034$|^5035$|^5046$|^5047$|^5048$|^5049$|^5051$|^5054$|^5057$|^5059$|^5060$|^5063$|^5063$ +^258$|^5001$|^5028$|^5036$|^5037$|^5038$|^5039$|^5040$|^5041$|^5053$|^5056$|^5061$|^5062$|^5065$ +^257$|^5000$|^5026$|^5052$|^5055$ +quarantined|moved to quarantine|file was deleted|deleted successfully|has been deleted|message deleted|deleted after|cleaned|successfully deleted +The file \.+ contain|infected with|User defined detection|scan found|error attempting to clean +10 + + + + 18101,18102,18103 + windows + ^McLogEvent + Grouping of McAfee Windows AV rules. + + + + 7500 + $MCAFEE_INFO + McAfee Windows AV informational event. + + + + 7500 + $MCAFEE_WARN + McAfee Windows AV warning event. + + + + 7500 + $MCAFEE_ERROR + McAfee Windows AV error event. + + + + 7500 + $MCAFEE_VIRUS + virus + McAfee Windows AV - Virus detected and not removed. + + + + 7504 + $MCAFEE_VIRUS_OK + virus + McAfee Windows AV - Virus detected and properly removed. + + + + 7504 + Will be deleted + virus + McAfee Windows AV - Virus detected and file will be deleted. + + + + 7500 + scan started|scan stopped + McAfee Windows AV - Scan started or stopped. + + + + 7501 + ^257 + completed. No detections + McAfee Windows AV - Scan completed with no viruses found. + + + + 7500 + scan was cancelled |has taken too long + McAfee Windows AV - Virus scan cancelled. + + + + 7500 + scan was canceled because + McAfee Windows AV - Virus scan cancelled due to shutdown. + + + + 7500 + update was successful + McAfee Windows AV - Virus program or DAT update succeeded. + + + + 7500 + update failed + McAfee Windows AV - Virus program or DAT update failed. + + + + 7500 + update was cancelled + McAfee Windows AV - Virus program or DAT update cancelled. + + + + 7505 + contains the EICAR test file + alert_by_email + McAfee Windows AV - EICAR test file detected. + + + + + + 7502 + Multiple McAfee AV warning events. + + + +