все приложения (конечный файл (через слэш), конечное приложение (через слэш))
Цитата |
---|
26.09.2014 15:31:12 C:\Windows\System32\cmd.exe Get access to file C:\Users\***\AppData\Local\Temp\pubring.tmp some access blocked test hips Delete file 26.09.2014 15:31:12 C:\Windows\System32\cmd.exe Get access to file C:\Users\***\AppData\Local\Temp\pubring.tmp some access blocked test hips Delete file |
+
на ESS 8 работает правило с масками
Цитата |
---|
Source applications: for all Target files: c:\users\\appdata\local\temp\pubring.tmp Target applications: c:\users\\appdata\local\temp\test_*.* |
26.09.2014 15:44:57 C:\Windows\System32\cmd.exe Get access to
file C:\Users\***\AppData\Local\Temp\pubring.tmp some access
blocked test_hips.bat Delete file
26.09.2014 15:44:57 C:\Windows\System32\cmd.exe Get access to
file C:\Users\**\AppData\Local\Temp\pubring.tmp some access
blocked test_hips.bat Delete file
+
такое работает в ESS 8, маска для конечных приложений. *.bat например.
Цитата |
---|
26.09.2014 16:07:55 C:\Windows\System32\cmd.exe Get access to file C:\Users\***\AppData\Local\Temp\pubring.tmp some access blocked test_hips.bat Delete file 26.09.2014 16:07:55 C:\Windows\System32\cmd.exe Get access to file C:\Users\***\AppData\Local\Temp\pubring.tmp some access blocked test_hips.bat Delete file |
Source applications:
for all
Target files:
c:\users\\appdata\local\temp\pubring.tmp
Target applications:
c:\users\\appdata\local\temp\*.bat