cancel
Showing results for 
Search instead for 
Did you mean: 
shakira
Level 10

HRC Errors in HipsShield.logs. What's going on?

There were thousands of these on one of our endpoints. What are they are why are they firing on McAfee Default rules as well as Custom Rules we created with the Wizard GUI?

McAfee Default Example:

08-21 13:42:57 [06744] HRC ERROR:

************

Rule {

    Class Files

    Id 1254

    level 2

    files { Include -e  -apn_txt:\\?*  -list IIS_Ftp_Dir

    }

    time { Include "*" }

    application { Exclude  "$IIS_BinDir\\inetinfo.exe"  -list IIS_Processes

            }

    user_name { Include "*" }

    dependencies -c -d 1240

    directives -c -d files:write

  }

ERROR: Section <files> has no values

REMOVED

Custom GUI Wizard Example:

08-21 13:42:57 [06744] HRC ERROR:

************

Rule {

tag "A Known Bad File Indicator"

Class Files

Id 5714

level 3

files { Include "*\\\\SYSTEM32\\reallybad.exe" }

directives files:execute files:rename files:delete filesSmiley Tongueermissions files:write files:attribute files:create

}

ERROR: Bad directive - filesSmiley Tongueermissions

REMOVED

************

Why is the bottom one saying filesSmiley Tongueermissions is a bad directive? The GUI made this rule when I checked the "Permissions" box.

0 Kudos
1 Reply
greatscott
Level 12

Re: HRC Errors in HipsShield.logs. What's going on?

you should open a ticket and see what they say. you could try removing the "permissions" setting and just using attributes, since I believe a change to permissions would be an attribute modification as well?

0 Kudos