All Products
Search
Document Center

Resource Orchestration Service:ALIYUN::ThreatDetection::ClientFileProtect

更新時間:Jul 06, 2026

Use the ALIYUN::ThreatDetection::ClientFileProtect resource to create a client file protection rule.

Syntax

{
  "Type": "ALIYUN::ThreatDetection::ClientFileProtect",
  "Properties": {
    "FilePaths": List,
    "FileOps": List,
    "ProcPaths": List,
    "RuleAction": String,
    "RuleName": String,
    "AlertLevel": Integer,
    "Platform": String,
    "Status": Integer,
    "SwitchId": String
  }
}

Properties

Parameter

Type

Required

Editable

Description

Constraints

FileOps

List

Yes

Yes

The operations to perform on the files.

None

FilePaths

List

Yes

Yes

The paths to the monitored files.

Wildcard characters are supported.

ProcPaths

List

Yes

Yes

The paths to the monitored processes.

None

RuleAction

String

Yes

Yes

The rule action.

Valid values:

  • pass: allow

  • alert: generates an alert

RuleName

String

Yes

Yes

The rule name.

None

AlertLevel

Integer

No

Yes

The alert severity.

Valid values:

  • 0: does not generate alerts

  • 1: sends notifications

  • 2: suspicious

  • 3: high-risk

Platform

String

No

No

The operating system type.

Valid values:

  • windows: Windows

  • linux: Linux

Status

Integer

No

No

The rule status.

Valid values:

1: Enabled

0: Disabled

SwitchId

String

No

No

The switch ID.

None

Return values

Fn::GetAtt

  • FilePaths: The paths to the monitored files. Wildcard characters are supported.

  • FileOps: The operations to perform on the files.

  • Platform: The operating system type.

  • RuleId: The rule ID.

  • RuleAction: The rule action.

  • ProcPaths: The paths to the monitored processes.

  • SwitchId: The switch ID.

  • AlertLevel: The alert severity.

  • RuleName: The rule name.

Examples

ROSTemplateFormatVersion: '2015-09-01'
Parameters:
  FileOps:
    Description:
      en: The operations that you want to perform on the files.
    Required: true
    Type: Json
    AssociationProperty: List[Parameter]
    AssociationPropertyMetadata:
      Parameter:
        Type: String
        Description:
          en: |-
            The operation that you want to perform on the file. Valid values:
            *   WRITE
            *   READ
            *   DELETE
            *   RENAME
            *   CHMOD: changes permissions.
        AllowedValues:
          - WRITE
          - READ
          - DELETE
          - RENAME
          - CHMOD
        Default: Null
        Required: false
  RuleName:
    Type: String
    Description:
      en: The rule name.
    Required: true
  Platform:
    Type: String
    Description:
      en: |-
        The operating system type. Valid values:
        *   **windows**: Windows
        *   **linux**: Linux
    AllowedValues:
      - windows
      - linux
    Default: Null
    Required: false
  Status:
    Type: Number
    Description:
      en: |-
        The rule status. Valid values:
        *   1: Enabled
        *   0: Disabled
    AllowedValues:
      - 0
      - 1
    Default: Null
    Required: false
  SwitchId:
    Type: String
    Description:
      en: The switch ID.
    Default: Null
    Required: false
  ProcPaths:
    Description:
      en: The paths to the monitored processes.
    Required: true
    Type: Json
    AssociationProperty: List[Parameter]
    AssociationPropertyMetadata:
      Parameter:
        Type: String
        Description:
          en: The path to the monitored process.
        Default: Null
        Required: false
  RuleAction:
    Type: String
    Description:
      en: |-
        The rule action. Valid values:
        *   pass: allow
        *   alert: generates an alert
    AllowedValues:
      - pass
      - alert
    Required: true
  FilePaths:
    Description:
      en: The paths to the monitored files. Wildcard characters are supported.
    Required: true
    Type: Json
    AssociationProperty: List[Parameter]
    AssociationPropertyMetadata:
      Parameter:
        Type: String
        Description:
          en: The path to the monitored file. Wildcard characters are supported.
        Default: Null
        Required: false
  AlertLevel:
    Type: Number
    Description:
      en: |-
        The alert severity. Valid values:
        *   0: does not generate alerts
        *   1: sends notifications
        *   2: suspicious
        *   3: high-risk
    AllowedValues:
      - 0
      - 1
      - 2
      - 3
    Default: Null
    Required: false
Resources:
  ExtensionResource:
    Type: ALIYUN::ThreatDetection::ClientFileProtect
    Properties:
      FileOps:
        Ref: FileOps
      RuleName:
        Ref: RuleName
      Platform:
        Ref: Platform
      Status:
        Ref: Status
      SwitchId:
        Ref: SwitchId
      ProcPaths:
        Ref: ProcPaths
      RuleAction:
        Ref: RuleAction
      FilePaths:
        Ref: FilePaths
      AlertLevel:
        Ref: AlertLevel
Outputs:
  FileOps:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - FileOps
    Description: The operations that you want to perform on the files.
  RuleId:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - RuleId
    Description: The rule ID.
  RuleName:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - RuleName
    Description: The rule name.
  Platform:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - Platform
    Description: The operating system type.
  SwitchId:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - SwitchId
    Description: The switch ID.
  ProcPaths:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - ProcPaths
    Description: The paths to the monitored processes.
  RuleAction:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - RuleAction
    Description: The rule action.
  FilePaths:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - FilePaths
    Description: The paths to the monitored files. Wildcard characters are supported.
  AlertLevel:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - AlertLevel
    Description: The alert severity.
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Parameters": {
    "FileOps": {
      "Description": {
        "en": "The operations that you want to perform on the files."
      },
      "Required": true,
      "Type": "Json",
      "AssociationProperty": "List[Parameter]",
      "AssociationPropertyMetadata": {
        "Parameter": {
          "Type": "String",
          "Description": {
            "en": "The operation that you want to perform on the file. Valid values:\n*   WRITE\n*   READ\n*   DELETE\n*   RENAME\n*   CHMOD: changes permissions."
          },
          "AllowedValues": [
            "WRITE",
            "READ",
            "DELETE",
            "RENAME",
            "CHMOD"
          ],
          "Default": null,
          "Required": false
        }
      }
    },
    "RuleName": {
      "Type": "String",
      "Description": {
        "en": "The rule name."
      },
      "Required": true
    },
    "Platform": {
      "Type": "String",
      "Description": {
        "en": "The operating system type. Valid values:\n*   **windows**: Windows\n*   **linux**: Linux"
      },
      "AllowedValues": [
        "windows",
        "linux"
      ],
      "Default": null,
      "Required": false
    },
    "Status": {
      "Type": "Number",
      "Description": {
        "en": "The rule status. Valid values:\n*   1: Enabled\n*   0: Disabled"
      },
      "AllowedValues": [
        0,
        1
      ],
      "Default": null,
      "Required": false
    },
    "SwitchId": {
      "Type": "String",
      "Description": {
        "en": "The switch ID."
      },
      "Default": null,
      "Required": false
    },
    "ProcPaths": {
      "Description": {
        "en": "The paths to the monitored processes."
      },
      "Required": true,
      "Type": "Json",
      "AssociationProperty": "List[Parameter]",
      "AssociationPropertyMetadata": {
        "Parameter": {
          "Type": "String",
          "Description": {
            "en": "The path to the monitored process."
          },
          "Default": null,
          "Required": false
        }
      }
    },
    "RuleAction": {
      "Type": "String",
      "Description": {
        "en": "The rule action. Valid values:\n*   pass: allow\n*   alert: generates an alert"
      },
      "AllowedValues": [
        "pass",
        "alert"
      ],
      "Required": true
    },
    "FilePaths": {
      "Description": {
        "en": "The paths to the monitored files. Wildcard characters are supported."
      },
      "Required": true,
      "Type": "Json",
      "AssociationProperty": "List[Parameter]",
      "AssociationPropertyMetadata": {
        "Parameter": {
          "Type": "String",
          "Description": {
            "en": "The path to the monitored file. Wildcard characters are supported."
          },
          "Default": null,
          "Required": false
        }
      }
    },
    "AlertLevel": {
      "Type": "Number",
      "Description": {
        "en": "The alert severity. Valid values:\n*   0: does not generate alerts\n*   1: sends notifications\n*   2: suspicious\n*   3: high-risk"
      },
      "AllowedValues": [
        0,
        1,
        2,
        3
      ],
      "Default": null,
      "Required": false
    }
  },
  "Resources": {
    "ExtensionResource": {
      "Type": "ALIYUN::ThreatDetection::ClientFileProtect",
      "Properties": {
        "FileOps": {
          "Ref": "FileOps"
        },
        "RuleName": {
          "Ref": "RuleName"
        },
        "Platform": {
          "Ref": "Platform"
        },
        "Status": {
          "Ref": "Status"
        },
        "SwitchId": {
          "Ref": "SwitchId"
        },
        "ProcPaths": {
          "Ref": "ProcPaths"
        },
        "RuleAction": {
          "Ref": "RuleAction"
        },
        "FilePaths": {
          "Ref": "FilePaths"
        },
        "AlertLevel": {
          "Ref": "AlertLevel"
        }
      }
    }
  },
  "Outputs": {
    "FileOps": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "FileOps"
        ]
      },
      "Description": "The operations that you want to perform on the files."
    },
    "RuleId": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "RuleId"
        ]
      },
      "Description": "The rule ID."
    },
    "RuleName": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "RuleName"
        ]
      },
      "Description": "The rule name."
    },
    "Platform": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "Platform"
        ]
      },
      "Description": "The operating system type."
    },
    "SwitchId": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "SwitchId"
        ]
      },
      "Description": "The switch ID."
    },
    "ProcPaths": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "ProcPaths"
        ]
      },
      "Description": "The paths to the monitored processes."
    },
    "RuleAction": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "RuleAction"
        ]
      },
      "Description": "The rule action."
    },
    "FilePaths": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "FilePaths"
        ]
      },
      "Description": "The paths to the monitored files. Wildcard characters are supported."
    },
    "AlertLevel": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "AlertLevel"
        ]
      },
      "Description": "The alert severity."
    }
  }
}