Policies and findings · GraphQL type

RuleBodyFile type

The body of a FILE rule. It checks only what your path sensors already collect: make sure a sensor covers the glob, and collects contents when the rule checks them.

A rule makes one kind of check. An existence check applies to Endpoint and raises one finding per endpoint; an endpoint no path sensor has collected on isn't judged. The contents, permissions, and ownership checks apply to EndpointPath, the files one path sensor collected on an endpoint, and raise one finding per failing file, keyed by the file's path. A file a check can't judge, such as one whose contents weren't collected, keeps its current findings until the check can. A file its sensor reports deleted counts as removed from the endpoint. Windows collects no file owners or meaningful permission bits, so a Windows glob can check only existence or contents.

Fields

Field Name Description
pathGlob - String! The paths checked, as an absolute glob such as /etc/ssh/sshd_config or /etc/cron.d/*. Each * stays within one directory. A Windows glob (starting with a drive letter or \) matches case-insensitively and accepts either slash.
pathSensorId - PathSensorId When set, only paths this path sensor collected are checked.
existence - RuleFileExistence Requires matching paths to be present or absent on each endpoint. See RuleFileExistence.
contents - RuleFileContents The content check each matching file must pass. See RuleFileContents.
permissions - RuleFilePermissions The permission check each matching file must pass. See RuleFilePermissions.
ownership - RuleFileOwnership The ownership check each matching file must pass. See RuleFileOwnership.

Used by

  • RuleBody union: A polymorphic body for a rule type.
  • RuleBodyFileInput input: Input variant of RuleBodyFile.
  • RuleType enum: Describes how a rule gathers the input its function evaluates.

Example

Example

{
  "pathGlob": "xyz789",
  "pathSensorId": PathSensorId,
  "existence": "MUST_EXIST",
  "contents": RuleFileContents,
  "permissions": RuleFilePermissions,
  "ownership": RuleFileOwnership
}