Policies and findings · GraphQL enum

RuleApplyToOptionKey enum

Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type. A key is only valid when the rule's applyTo type can resolve it; invalid keys are rejected when the rule is saved. CONFIGURATION rules accept any key their applyTo type can resolve; FILE, PROPRIETARY, SEARCH, THRESHOLD, and VULNERABILITY rules accept only a single OS option with the EQUALS operator. See RuleApplyToOption.

Values

Enum Value Description

OS

Operating system platform. The value must be an OsPlatform (WINDOWS, DARWIN, LINUX). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

OS_VERSION

Operating system version (for example 14.4). The value must be a parseable version string. Supports the ordering operators; IN and NOT_IN are not supported.

MACHINE_ROLE

The host's machine/domain role. The value must be an ActiveDirectoryRole other than NOT_SET. Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

LINUX_DISTRIBUTION

Linux distribution (for example UBUNTU, RHEL). The value must be a LinuxDistribution. Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

OS_EDITION

Operating system edition/SKU. The value must be a WindowsEdition (for example ENTERPRISE, PROFESSIONAL), resolved from the endpoint's system information. Windows-only: non-Windows hosts carry no structured edition, and UNKNOWN is rejected. Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

CHASSIS_TYPE

Hardware chassis type. The value must be a ChassisType (for example LAPTOP, NOTEBOOK, PORTABLE, DESKTOP, TOWER, TABLET), resolved from the endpoint's system information. UNKNOWN and OTHER are rejected. Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

SERVICE_START_TYPE

Service start type. Valid only when the rule's applyTo is SystemService; the value is resolved from the service object itself, not the endpoint. The value must be a ServiceStartType other than UNKNOWN (for example AUTO_START, DISABLED). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

USER_TYPE

User account classification. Valid only when the rule's applyTo is EndpointUser; the value is resolved from the user object itself, not the endpoint. The value must be an EndpointUserType other than UNKNOWN (LOCAL, DOMAIN, SYSTEM). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

DISK_BUS_TYPE

Disk hardware bus type. Valid only when the rule's applyTo is Disk; the value is resolved from the disk object itself, not the endpoint. The value must be a BusType other than UNKNOWN (for example USB, NVME, SATA, VIRTUAL). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

NETWORK_TYPE

Network classification. Valid only when the rule's applyTo is Network; the value is resolved from the network object itself. The value must be a NetworkType (PREMISE, REMOTE, LINK_LOCAL). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

DEVICE_TYPE

Device category. Valid only when the rule's applyTo is Device; the value is resolved from the device's fingerprint result. The value must be a DeviceTypeCategory other than UNKNOWN (for example PRINTER, CAMERA, IOT_DEVICE). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

DEVICE_IS_GATEWAY

Whether the device is a network gateway. Valid only when the rule's applyTo is Device; the value is resolved from the device object itself. The value is "true" or "false". Supports EQUALS and NOT_EQUAL.

SERVICE_TYPE

Observed network-service type. Valid only when the rule's applyTo is Service; the value is resolved from the service object itself. The value must be a ServiceType other than UNKNOWN (for example SSH, HTTPS, SMB). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

PUBLICLY_EXPOSED

Whether the object is reachable from a public network. Valid when the rule's applyTo is Service or OpenPort; the value is resolved from the object itself. The value is "true" or "false". Supports EQUALS and NOT_EQUAL.

IP_PROTOCOL

IP transport protocol. Valid only when the rule's applyTo is OpenPort; the value is resolved from the port object itself. The value must be an IpProtocol other than UNKNOWN (TCP, UDP). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

INTERFACE_TYPE

Network interface type (IANA ifType). Valid only when the rule's applyTo is Interface; the value is resolved from the interface object itself. The value must be an InterfaceType other than OTHER (for example ETHERNET_CSMACD, IEEE_80211, SOFTWARE_LOOPBACK). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

INTERFACE_IS_LOOPBACK

Whether the interface is a loopback interface. Valid only when the rule's applyTo is Interface; the value is resolved from the interface object itself. The value is "true" or "false". Supports EQUALS and NOT_EQUAL.

WLAN_RADIO_STATE

Wireless radio state. Valid only when the rule's applyTo is WlanInterface; the value is resolved from the interface object itself. The value must be a WlanInterfaceRadioState other than UNKNOWN (ON, OFF). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

WLAN_CONNECTION_STATE

Wireless connection state. Valid only when the rule's applyTo is WlanInterface; the value is resolved from the interface object itself. The value must be a WlanInterfaceConnectionState other than UNKNOWN (for example CONNECTED, DISCONNECTED, ADHOC). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

WLAN_MODE

Wireless radio mode. Valid when the rule's applyTo is WlanNetwork or WlanAccessPoint; the value is resolved from the object itself. The value must be a WlanInterfaceMode other than UNKNOWN (for example INFRA_AP, INFRA_NON_AP, IBSS, MESH). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

WLAN_CHANNEL_BAND

Wireless frequency band. Valid only when the rule's applyTo is WlanAccessPoint; the value is resolved from the access-point object itself. The value must be a WlanChannelBand other than UNKNOWN (GHZ_2, GHZ_5, GHZ_6). Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

FILESYSTEM_TYPE

Mounted filesystem type. Valid only when the rule's applyTo is DiskMount; the value is resolved from the mount object itself. It is a free-form string (for example ext4, xfs, apfs, ntfs, tmpfs) — there is no closed enum. Supports EQUALS, NOT_EQUAL, IN and NOT_IN.

LOCATION_KNOWN

Whether the position has a resolved geolocation. Valid only when the rule's applyTo is PositionSeen; the value is resolved from the position object itself. The value is "true" or "false". Supports EQUALS and NOT_EQUAL.

Used by

Related types

  • Device A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
  • Disk A physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…
  • DiskMount A file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).
  • EndpointUser An operating system or domain user account observed on an Endpoint.
  • Interface A network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…
  • Network An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
  • OpenPort One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
  • PositionSeen A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.
  • Service A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
  • SystemService A background service or daemon configured on an Endpoint.
  • WlanAccessPoint A Wi-Fi access point radio, identified by the network name (SSID) it broadcasts and its BSSID, as heard by managed endpoints scanning for nearby…
  • WlanInterface A wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.
  • WlanNetwork A Wi-Fi network identified by its network name (SSID), visible to managed endpoints when they scan for nearby networks on Windows, macOS, or Linux.

Example

Example

"OS"