Use the ALIYUN::ThreatDetection::ClientFileProtect resource to create a client file protection rule.
Syntax
{
"Type": "ALIYUN::ThreatDetection::ClientFileProtect",
"Properties": {
"FilePaths": List,
"FileOps": List,
"ProcPaths": List,
"RuleAction": String,
"RuleName": String,
"AlertLevel": Integer,
"Platform": String,
"Status": Integer,
"SwitchId": String
}
}Properties
Parameter | Type | Required | Editable | Description | Constraints |
FileOps | List | Yes | Yes | The operations to perform on the files. | None |
FilePaths | List | Yes | Yes | The paths to the monitored files. | Wildcard characters are supported. |
ProcPaths | List | Yes | Yes | The paths to the monitored processes. | None |
RuleAction | String | Yes | Yes | The rule action. | Valid values:
|
RuleName | String | Yes | Yes | The rule name. | None |
AlertLevel | Integer | No | Yes | The alert severity. | Valid values:
|
Platform | String | No | No | The operating system type. | Valid values:
|
Status | Integer | No | No | The rule status. | Valid values: 1: Enabled 0: Disabled |
SwitchId | String | No | No | The switch ID. | None |
Return values
Fn::GetAtt
FilePaths: The paths to the monitored files. Wildcard characters are supported.
FileOps: The operations to perform on the files.
Platform: The operating system type.
RuleId: The rule ID.
RuleAction: The rule action.
ProcPaths: The paths to the monitored processes.
SwitchId: The switch ID.
AlertLevel: The alert severity.
RuleName: The rule name.
Examples
ROSTemplateFormatVersion: '2015-09-01'
Parameters:
FileOps:
Description:
en: The operations that you want to perform on the files.
Required: true
Type: Json
AssociationProperty: List[Parameter]
AssociationPropertyMetadata:
Parameter:
Type: String
Description:
en: |-
The operation that you want to perform on the file. Valid values:
* WRITE
* READ
* DELETE
* RENAME
* CHMOD: changes permissions.
AllowedValues:
- WRITE
- READ
- DELETE
- RENAME
- CHMOD
Default: Null
Required: false
RuleName:
Type: String
Description:
en: The rule name.
Required: true
Platform:
Type: String
Description:
en: |-
The operating system type. Valid values:
* **windows**: Windows
* **linux**: Linux
AllowedValues:
- windows
- linux
Default: Null
Required: false
Status:
Type: Number
Description:
en: |-
The rule status. Valid values:
* 1: Enabled
* 0: Disabled
AllowedValues:
- 0
- 1
Default: Null
Required: false
SwitchId:
Type: String
Description:
en: The switch ID.
Default: Null
Required: false
ProcPaths:
Description:
en: The paths to the monitored processes.
Required: true
Type: Json
AssociationProperty: List[Parameter]
AssociationPropertyMetadata:
Parameter:
Type: String
Description:
en: The path to the monitored process.
Default: Null
Required: false
RuleAction:
Type: String
Description:
en: |-
The rule action. Valid values:
* pass: allow
* alert: generates an alert
AllowedValues:
- pass
- alert
Required: true
FilePaths:
Description:
en: The paths to the monitored files. Wildcard characters are supported.
Required: true
Type: Json
AssociationProperty: List[Parameter]
AssociationPropertyMetadata:
Parameter:
Type: String
Description:
en: The path to the monitored file. Wildcard characters are supported.
Default: Null
Required: false
AlertLevel:
Type: Number
Description:
en: |-
The alert severity. Valid values:
* 0: does not generate alerts
* 1: sends notifications
* 2: suspicious
* 3: high-risk
AllowedValues:
- 0
- 1
- 2
- 3
Default: Null
Required: false
Resources:
ExtensionResource:
Type: ALIYUN::ThreatDetection::ClientFileProtect
Properties:
FileOps:
Ref: FileOps
RuleName:
Ref: RuleName
Platform:
Ref: Platform
Status:
Ref: Status
SwitchId:
Ref: SwitchId
ProcPaths:
Ref: ProcPaths
RuleAction:
Ref: RuleAction
FilePaths:
Ref: FilePaths
AlertLevel:
Ref: AlertLevel
Outputs:
FileOps:
Value:
Fn::GetAtt:
- ExtensionResource
- FileOps
Description: The operations that you want to perform on the files.
RuleId:
Value:
Fn::GetAtt:
- ExtensionResource
- RuleId
Description: The rule ID.
RuleName:
Value:
Fn::GetAtt:
- ExtensionResource
- RuleName
Description: The rule name.
Platform:
Value:
Fn::GetAtt:
- ExtensionResource
- Platform
Description: The operating system type.
SwitchId:
Value:
Fn::GetAtt:
- ExtensionResource
- SwitchId
Description: The switch ID.
ProcPaths:
Value:
Fn::GetAtt:
- ExtensionResource
- ProcPaths
Description: The paths to the monitored processes.
RuleAction:
Value:
Fn::GetAtt:
- ExtensionResource
- RuleAction
Description: The rule action.
FilePaths:
Value:
Fn::GetAtt:
- ExtensionResource
- FilePaths
Description: The paths to the monitored files. Wildcard characters are supported.
AlertLevel:
Value:
Fn::GetAtt:
- ExtensionResource
- AlertLevel
Description: The alert severity.
{
"ROSTemplateFormatVersion": "2015-09-01",
"Parameters": {
"FileOps": {
"Description": {
"en": "The operations that you want to perform on the files."
},
"Required": true,
"Type": "Json",
"AssociationProperty": "List[Parameter]",
"AssociationPropertyMetadata": {
"Parameter": {
"Type": "String",
"Description": {
"en": "The operation that you want to perform on the file. Valid values:\n* WRITE\n* READ\n* DELETE\n* RENAME\n* CHMOD: changes permissions."
},
"AllowedValues": [
"WRITE",
"READ",
"DELETE",
"RENAME",
"CHMOD"
],
"Default": null,
"Required": false
}
}
},
"RuleName": {
"Type": "String",
"Description": {
"en": "The rule name."
},
"Required": true
},
"Platform": {
"Type": "String",
"Description": {
"en": "The operating system type. Valid values:\n* **windows**: Windows\n* **linux**: Linux"
},
"AllowedValues": [
"windows",
"linux"
],
"Default": null,
"Required": false
},
"Status": {
"Type": "Number",
"Description": {
"en": "The rule status. Valid values:\n* 1: Enabled\n* 0: Disabled"
},
"AllowedValues": [
0,
1
],
"Default": null,
"Required": false
},
"SwitchId": {
"Type": "String",
"Description": {
"en": "The switch ID."
},
"Default": null,
"Required": false
},
"ProcPaths": {
"Description": {
"en": "The paths to the monitored processes."
},
"Required": true,
"Type": "Json",
"AssociationProperty": "List[Parameter]",
"AssociationPropertyMetadata": {
"Parameter": {
"Type": "String",
"Description": {
"en": "The path to the monitored process."
},
"Default": null,
"Required": false
}
}
},
"RuleAction": {
"Type": "String",
"Description": {
"en": "The rule action. Valid values:\n* pass: allow\n* alert: generates an alert"
},
"AllowedValues": [
"pass",
"alert"
],
"Required": true
},
"FilePaths": {
"Description": {
"en": "The paths to the monitored files. Wildcard characters are supported."
},
"Required": true,
"Type": "Json",
"AssociationProperty": "List[Parameter]",
"AssociationPropertyMetadata": {
"Parameter": {
"Type": "String",
"Description": {
"en": "The path to the monitored file. Wildcard characters are supported."
},
"Default": null,
"Required": false
}
}
},
"AlertLevel": {
"Type": "Number",
"Description": {
"en": "The alert severity. Valid values:\n* 0: does not generate alerts\n* 1: sends notifications\n* 2: suspicious\n* 3: high-risk"
},
"AllowedValues": [
0,
1,
2,
3
],
"Default": null,
"Required": false
}
},
"Resources": {
"ExtensionResource": {
"Type": "ALIYUN::ThreatDetection::ClientFileProtect",
"Properties": {
"FileOps": {
"Ref": "FileOps"
},
"RuleName": {
"Ref": "RuleName"
},
"Platform": {
"Ref": "Platform"
},
"Status": {
"Ref": "Status"
},
"SwitchId": {
"Ref": "SwitchId"
},
"ProcPaths": {
"Ref": "ProcPaths"
},
"RuleAction": {
"Ref": "RuleAction"
},
"FilePaths": {
"Ref": "FilePaths"
},
"AlertLevel": {
"Ref": "AlertLevel"
}
}
}
},
"Outputs": {
"FileOps": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"FileOps"
]
},
"Description": "The operations that you want to perform on the files."
},
"RuleId": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"RuleId"
]
},
"Description": "The rule ID."
},
"RuleName": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"RuleName"
]
},
"Description": "The rule name."
},
"Platform": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"Platform"
]
},
"Description": "The operating system type."
},
"SwitchId": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"SwitchId"
]
},
"Description": "The switch ID."
},
"ProcPaths": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"ProcPaths"
]
},
"Description": "The paths to the monitored processes."
},
"RuleAction": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"RuleAction"
]
},
"Description": "The rule action."
},
"FilePaths": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"FilePaths"
]
},
"Description": "The paths to the monitored files. Wildcard characters are supported."
},
"AlertLevel": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"AlertLevel"
]
},
"Description": "The alert severity."
}
}
}