屬性類型 & 關係、符號
屬性類型 & 關聯(條件屬性)。
|
is(not)set |
is(not) |
is(not)empty |
(not)starts |
(not)contains |
(not)ends |
less, lessOrEqual, greater, greaterOrEqual |
|---|---|---|---|---|---|---|---|
字串 |
✔ |
✔ |
✔ |
✔ |
✔ |
✔ |
|
符號 |
✔ |
✔ |
✔ |
|
✔ |
|
|
int |
✔ |
✔ |
✔ |
|
✔ |
|
✔ |
bool |
✔ |
✔ |
|
|
|
|
|
日期 |
✔ |
✔ |
|
|
|
|
✔ |
雜湊 |
✔ |
✔ |
✔ |
|
|
|
|
UUID |
✔ |
✔ |
|
|
|
|
|
路徑 |
✔ |
✔ |
✔ |
✔ |
✔ |
|
|
IPv4 位址 |
✔ |
✔ |
✔ |
|
|
|
|
IPv6 位址 |
✔ |
✔ |
✔ |
|
|
|
|
值集合 |
✔ |
|
✔ |
|
✔ |
|
|
符號
當指定要用來比對的屬性值時:
<condition component="ApiCall" property="ApiName" condition="is" value="RegisterRawInputDevices"/> |
對於 Symbol 屬性類型,您可以使用預先定義符號的整數代碼或字串值。
例如,對於 ApiCall 元件和 ApiName 屬性,支援的值為:
•0—SetWinEventHook
•1—SetWindowsHookEx
•2—RegisterRawInputDevices
•3—GetAsyncKeyState
•4—UiLimitWriteClipboard
•5—UiWriteClipboard
•6—CredEnumerate
•7—CredReadDomainCredentials
•8—CredFindBestCredential
•9—CredBackupCredentials
•10—CredRead
•11—CredReadByTokenHandle
•12—VaultEnumerateCredentials
•21845—RawSocketCreated
•21846—SocketFilterAttached
您可以使用整數代碼 2 作為值:
<condition component="ApiCall" property="ApiName" condition="is" value="2"/> |
或字串值 RegisterRawInputDevices:
<condition component="ApiCall" property="ApiName" condition="is" value="RegisterRawInputDevices"/> |
目前符號類型實作於以下元件中:
•ApiCall,針對屬性 ApiName
•BitsJobAddFile,適用於屬性 SidNameUse
•ClientModule,適用於屬性 FileOrigin、SignatureType、Whitelist
•ClientProcessInfo,屬性為 IntegrityLevel
•CodeInjectionInfo,針對屬性 CodeInjectionType
•DnsInfo,針對屬性 DnsResponseType
•DoneByUser,屬性為 SidNameUse
•Endpoint,適用於屬性 DetectionType、Scanner、ScannerObjectType、Severity
•FileAttribute,屬性為 Attribute
•InspectDetection,屬性為 RuleSeverity
•Module,適用於內容 FileOrigin、SignatureType、Whitelist
•OpenProcess,屬性為 AccessRight
•ProcessInfo,針對屬性 IntegrityLevel
•ScheduledTask,屬性為 Type
•Service,屬性為 LoadType
•ServiceProcessInfo,屬性為 IntegrityLevel
•SystemInfo,對於屬性 SystemArchitecture、SystemType
•TargetUser,屬性為 SidNameUse
•UserGroupData,屬性為 SidNameUse
•UserLogonData,針對屬性 LogonType