Select the tab
ESET Inspect On-Prem – Table of Contents

ProcessBehavior

ProcessBehavior events are reported on Windows. Antivirus tracks which files were accessed and how frequently. If the process accessed more files than are set in the barrier in a certain time period, this event is reported.

Property

Type

Description

Example

FileOperations

String

Operations and their barriers

Possbile values are:

0—Unknown

1—WrBarrier1

2—WrBarrier2

3—RenameBarrier1

4—RenameBarrier2

5—MultiextWrBarrier1

6—MultiextWrBarrier2

7—MultiextRenameBarrier1

8—MultiextRenameBarrier2

9—BlobDetection


Note

The FileOperations values are internal and are intended to be used only with default rules.

Supported operations

MultipleFilesChanged