Policies and findings · GraphQL type

RuleFileContents type

A FILE rule's content check. Every condition set must hold. Pattern checks need the path sensor to collect contents; when the collected contents were cut short, a pattern that isn't found proves nothing and the file keeps its current findings. Patterns use RE2 syntax limited to ASCII: they can't name a character beyond ASCII or use a \p or \P class, though . and \S still match any character.

Fields

Field Name Description
mustMatch - String A regular expression (RE2 syntax) the collected contents must match.
mustNotMatch - String A regular expression (RE2 syntax) the collected contents must not match.
checksum - String The xxh3-128 checksum, as 32 hex characters, the file must have: the digest path sensors collect.

Used by

Example

Example

{
  "mustMatch": "abc123",
  "mustNotMatch": "abc123",
  "checksum": "xyz789"
}