Templates and Alerts
Modification of Files/Directories Template
File Being Modified
This template generates and forwards the following alert to a response program when a file is modified:
Table | File Being Modified Alert Properties |
| |||
|
|
|
|
|
|
| Response | Alert | Alert |
|
|
| Program | Field | Alert Value/Format | Description | |
| Field | ||||
| Argument | Type |
|
| |
|
|
|
| ||
|
|
|
|
|
|
| argv[1] | Template | Integer | 2 | Unique code |
|
| code |
|
| assigned to |
|
|
|
|
| template |
|
|
|
|
|
|
| argv[2] | Version | Integer | 2 | Version of the |
|
|
|
|
| template |
|
|
|
|
|
|
| argv[3] | Severity | Integer | 2 if file is truncated, potentially truncated, | Severity |
|
|
|
| deleted, or renamed. |
|
|
|
|
| 3 if file’s mode or ownership is modified, or |
|
|
|
|
| file is created, or file is opened for writing or |
|
|
|
|
| appending. |
|
|
|
|
|
|
|
| argv[4] | UTC Time | Integer | <secs> | UTC time in |
|
|
|
|
| number of seconds |
|
|
|
|
| since epoch when |
|
|
|
|
| file is modified. |
|
|
|
|
|
|
| argv[5] | Attacker | String | “uid=<uid>, gid=<gid>, pid=<pid>, | The user ID, group |
|
|
|
| ppid=<ppid>” | ID, process ID, |
|
|
|
|
| and parent |
|
|
|
|
| process ID of the |
|
|
|
|
| process that |
|
|
|
|
| modified the file. |
|
|
|
|
|
|
| argv[6] | Target of | String | “file=<full pathname>, | The full pathname |
|
| Attack |
| mode=<mode>,uid=<uid>,gid=<gid>, | of the file that was |
|
|
|
| modified and the | |
|
|
|
|
| |
|
|
|
| inode=<inode>,device=<device>” | file’s mode, uid, |
|
|
|
|
| gid, inode, and |
|
|
|
|
| device number. |
|
|
|
|
|
|
| argv[7] | Summary | String | “Filesystem modification or potential | Alert summary |
|
|
|
| modification” |
|
|
|
|
|
|
|
Appendix A | 149 |