CriteriaЕxt |
criteria_id |
Recommended |
Integer |
The criteria that is associated with the rule.
0 | Unknown | | |
1 | Antispyware is installed | | |
2 | Antispyware is running | | |
3 | Antispyware signature file is up to date | | |
4 | Antivirus is installed | | |
5 | Antivirus is running | | |
6 | Antivirus signature file is up to date | | |
7 | File age | | |
8 | File date | | |
9 | File size | | |
10 | File version | | |
11 | File download complete | | |
12 | File exists | | |
13 | File fingerprint matches | | |
14 | File executed successfully | | |
15 | Firewall is installed | | |
16 | Firewall is running | | |
17 | Patch version matches | | |
18 | Patch is installed | | |
19 | Registry value incremented successfully | | |
20 | Registry key exists | | |
21 | Registry value matches | | |
22 | Registry value exists | | |
23 | Registry value changed successfully | | |
24 | Timestamp matches | | |
25 | Message dialog return value | | |
26 | Operating system matches | | |
27 | Operating system language | | |
28 | Process is running | | |
29 | Service is running | | |
30 | File deleted successfully | | |
31 | Service pack version matches | | |
32 | Host Integrity installed | | |
33 | Remediation status | | |
34 | Custom Rule Enforcement | | |
35 | Check for unremediated threats | | |
36 | Device risk score matches | | |
37 | Client security assessment | | |
38 | Indicator of compromise exists | | |
39 | Indicator of compromise matches | | |
40 | Configuration vulnerability exists | | |
41 | Configuration vulnerability matches | | |
42 | Malware exists | | |
43 | Unwanted application exists | | |
44 | Outdated OS matches | | |
45 | Device compromised | | |
46 | Device emulator | | |
47 | MDM managed | | |
48 | Client installation health | | |
49 | Device protected | | |
50 | Device admin | | |
51 | Device model allowed | | |
52 | Device model denied | | |
53 | Application classification matches | | |
|
Rule DescriptionЕxt |
desc |
Recommended |
String |
The description of the rule. |
Rule Name |
name |
Recommended |
String |
The name given to the rule. |
Rule Type |
type_id |
Recommended |
Integer |
The type of the rule.
0 | Unknown | | |
1 | Malware Protection Enforcement | | |
2 | Patch Enforcement | | |
3 | Service Pack Enforcement | | |
4 | Firewall Enforcement | | |
5 | Custom Rule Enforcement | | |
6 | Configuration Enforcement | | |
7 | Vulnerability Scan | | |
8 | Mobile Rule Enforcement | | |
|
Rule IDЕxt |
uid |
Recommended |
String |
The unique identifier of the rule. |