Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

App Control: What Syntax to Use to Specify Approving Files With OnlyIF Macro and COMPANY Attribute.

App Control: What Syntax to Use to Specify Approving Files With OnlyIF Macro and COMPANY Attribute.

Environment

  • App Control Server: 8.0.x and Higher
  • App Control Agent: 8.0.x and Higher

Objective

  • This article contains the syntax for specifying the OnlyIF macro for COMPANY in a custom rule

Resolution

  • The three first fields need to be separated with colons
  • The section in the first <> is the OnlyIf which doesn't support wildcards in the file path
  • If the OnlyIf matches on the file then the PATHTO will be evaluated and this field does support wildcards
  • <OnlyIf:Company:*Carbon Black*:<ProgramFilesx86>\bit9\parity agent\parity.exe>PATHTO\*.EXE

     

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎12-03-2023
Views:
145
Contributors