X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=etc%2Frules%2Fms-se_rules.xml;fp=etc%2Frules%2Fms-se_rules.xml;h=fdfa23fa50a9af872b3243c81c5d39f9b7aa75b8;hp=91c024c8b6ae988974f2c5c8f259980211106f52;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b diff --git a/etc/rules/ms-se_rules.xml b/etc/rules/ms-se_rules.xml old mode 100755 new mode 100644 index 91c024c..fdfa23f --- a/etc/rules/ms-se_rules.xml +++ b/etc/rules/ms-se_rules.xml @@ -19,31 +19,39 @@ windows + 18101,18102,18103 ^Microsoft Antimalware Grouping of Microsoft Security Essentials rules. 7701 - ^1008$ + ^1118$|^1119$ virus Microsoft Security Essentials - Virus detected, but unable to remove. 7701 - ^1007$ + ^1107$ virus Microsoft Security Essentials - Virus detected and properly removed. 7701 - ^1015$|^1006$ + ^1119$|^1118$|^1117$|^1116$ virus Microsoft Security Essentials - Virus detected. - + + + 7701 + ^1015$ + virus, + Microsoft Security Essentials - Suspicious activity detected. + + 7701 ^5007$ @@ -51,6 +59,55 @@ policy_changed, + + 7701 + ^5008$ + Microsoft Security Essentials - Service failed. + + + + 7701 + ^3002$ + Microsoft Security Essentials - Real time protection failed. + + + + 7701 + ^2012$ + Microsoft Security Essentials - Cannot use Dynamic Signature Service. + + + + 7701 + ^2004$ + Microsoft Security Essentials - Loading definitions failed. Using last good set. + + + + 7701 + ^2003$ + Microsoft Security Essentials - Engine update failed. + + + + 7701 + ^2001$ + Microsoft Security Essentials - Definitions update failed. + + + + 7701 + ^1005$ + Microsoft Security Essentials - Scan error. Scan has stopped. + + + + 7701 + ^1002$ + Microsoft Security Essentials - Scan stopped before completion. + + + 7711, 7712 Virus:DOS/EICAR_Test_File