
Templates and Alerts
Modification of Files/Directories Template
File Being Modified
This template generates and forwards the following alert to a response program when a file is modified:
| Table  | File Being Modified Alert Properties | 
 | |||
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | Response | Alert | Alert | 
 | 
 | 
| 
 | Program | Field | Alert Value/Format | Description | |
| 
 | Field | ||||
| 
 | Argument | Type | 
 | 
 | |
| 
 | 
 | 
 | 
 | ||
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[1] | Template | Integer | 2 | Unique code | 
| 
 | 
 | code | 
 | 
 | assigned to | 
| 
 | 
 | 
 | 
 | 
 | template | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[2] | Version | Integer | 2 | Version of the | 
| 
 | 
 | 
 | 
 | 
 | template | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[3] | Severity | Integer | 2 if file is truncated, potentially truncated, | Severity | 
| 
 | 
 | 
 | 
 | deleted, or renamed. | 
 | 
| 
 | 
 | 
 | 
 | 3 if file’s mode or ownership is modified, or | 
 | 
| 
 | 
 | 
 | 
 | file is created, or file is opened for writing or | 
 | 
| 
 | 
 | 
 | 
 | appending. | 
 | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[4] | UTC Time | Integer | <secs> | UTC time in | 
| 
 | 
 | 
 | 
 | 
 | number of seconds | 
| 
 | 
 | 
 | 
 | 
 | since epoch when | 
| 
 | 
 | 
 | 
 | 
 | file is modified. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[5] | Attacker | String | “uid=<uid>, gid=<gid>, pid=<pid>, | The user ID, group | 
| 
 | 
 | 
 | 
 | ppid=<ppid>” | ID, process ID, | 
| 
 | 
 | 
 | 
 | 
 | and parent | 
| 
 | 
 | 
 | 
 | 
 | process ID of the | 
| 
 | 
 | 
 | 
 | 
 | process that | 
| 
 | 
 | 
 | 
 | 
 | modified the file. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[6] | Target of | String | “file=<full pathname>, | The full pathname | 
| 
 | 
 | Attack | 
 | mode=<mode>,uid=<uid>,gid=<gid>, | of the file that was | 
| 
 | 
 | 
 | 
 | modified and the | |
| 
 | 
 | 
 | 
 | 
 | |
| 
 | 
 | 
 | 
 | inode=<inode>,device=<device>” | file’s mode, uid, | 
| 
 | 
 | 
 | 
 | 
 | gid, inode, and | 
| 
 | 
 | 
 | 
 | 
 | device number. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[7] | Summary | String | “Filesystem modification or potential | Alert summary | 
| 
 | 
 | 
 | 
 | modification” | 
 | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| Appendix A | 149 | 
