Policies and findings · GraphQL enum

RuleType enum

Describes how a rule gathers the input its function evaluates. The type determines which body the rule carries — see RuleBody.

Values

Enum Value Description

CONFIGURATION

The rule checks an object's attributes against a required state. Evaluated whenever that object changes, so it carries no schedule. Its body is RuleBodyConfiguration.

FILE

The rule checks the files your path sensors collect: that they exist or don't on each Endpoint, or that each matching file a sensor collected, listed on its EndpointPath, meets the rule's content, permission, and ownership expectations, one finding per failing file. Runs on the rule's Schedule. Its body is RuleBodyFile.

PROPRIETARY

The rule runs a check that ships with the platform rather than one authored as rule content, so it carries no query or function of its own. Runs on the rule's Schedule. Its body is RuleBodyProprietary.

SEARCH

The rule flags every object its graph search finds, and clears the finding once an object no longer matches. Runs on the rule's Schedule. Its body is RuleBodySearch.

THRESHOLD

The rule counts, for each object it applies to, the related objects its count path reaches, and flags every object whose count falls below its minimum or above its maximum. Runs on the rule's Schedule. Its body is RuleBodyThreshold.

VULNERABILITY

The rule matches the CPEs on the objects it applies to against known CVEs, raising a finding and issue for each vulnerability it identifies, or one per object listing them all. Runs on the rule's Schedule. Its body is RuleBodyVulnerability.

Used by

  • Finding type: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
  • Issue type: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
  • Rule type: A policy rule evaluated against graph objects.
  • RuleInput input: Input variant of Rule carrying its writable fields.

Related types

  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • EndpointPath The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…

Example

Example

"CONFIGURATION"