|
| enum | doca_apsh_system_os { DOCA_APSH_SYSTEM_LINUX = 0
, DOCA_APSH_SYSTEM_WINDOWS = 1
} |
| | system os types More...
|
| |
| enum | doca_apsh_system_config_attr {
DOCA_APSH_OS_SYMBOL_MAP = 0
, DOCA_APSH_MEM_REGION = 1
, DOCA_APSH_KPGD_FILE = 2
, DOCA_APSH_VHCA_ID = 3
,
DOCA_APSH_OS_TYPE = 4
, DOCA_APSH_SCAN_WIN_SIZE = 5
, DOCA_APSH_SCAN_WIN_STEP = 6
, DOCA_APSH_HASHTEST_LIMIT = 7
,
DOCA_APSH_MODULES_LIMIT = 8
, DOCA_APSH_PROCESS_LIMIT = 9
, DOCA_APSH_THREADS_LIMIT = 10
, DOCA_APSH_LDRMODULES_LIMIT = 11
,
DOCA_APSH_LIBS_LIMIT = 12
, DOCA_APSH_VADS_LIMIT = 13
, DOCA_APSH_WINDOWS_ENVARS_LIMIT = 14
, DOCA_APSH_HANDLES_LIMIT = 15
,
DOCA_APSH_STRING_LIMIT = 16
, DOCA_APSH_OS_SYMBOL_MAP_FOLDER = 17
, DOCA_APSH_FILESIZE_LIMIT = 18
} |
| | doca app shield configuration attributes More...
|
| |
| enum | doca_apsh_process_attr {
DOCA_APSH_PROCESS_PID = 0
, DOCA_APSH_PROCESS_PPID = 1
, DOCA_APSH_PROCESS_COMM = 2
, DOCA_APSH_PROCESS_CPU_TIME = 3
,
DOCA_APSH_PROCESS_WINDOWS_OFFSET = 1000
, DOCA_APSH_PROCESS_WINDOWS_THREADS = 1001
, DOCA_APSH_PROCESS_WINDOWS_EXIT_TIME = 1002
, DOCA_APSH_PROCESS_LINUX_GID = 2000
,
DOCA_APSH_PROCESS_LINUX_UID = 2001
, DOCA_APSH_PROCESS_LINUX_STATE = 2002
, DOCA_APSH_PROCESS_LINUX_NS_PID = 2003
, DOCA_APSH_PROCESS_LINUX_NS_MNT = 2004
,
DOCA_APSH_PROCESS_LINUX_NS_NET = 2005
} |
| | doca app shield process attributes More...
|
| |
| enum | doca_apsh_thread_attr {
DOCA_APSH_THREAD_PID = 0
, DOCA_APSH_THREAD_TID = 1
, DOCA_APSH_THREAD_STATE = 2
, DOCA_APSH_THREAD_WINDOWS_WAIT_REASON = 1000
,
DOCA_APSH_THREAD_WINDOWS_OFFSET = 1001
, DOCA_APSH_THREAD_WINDOWS_SUSPEND_COUNT = 1002
, DOCA_APSH_THREAD_LINUX_PROC_NAME = 2000
, DOCA_APSH_THREAD_LINUX_THREAD_NAME = 2001
} |
| | doca app shield thread attributes More...
|
| |
| enum | doca_apsh_lib_attr {
DOCA_APSH_LIB_PID = 0
, DOCA_APSH_LIB_LIBRARY_PATH = 2
, DOCA_APSH_LIB_LOAD_ADRESS = 3
, DOCA_APSH_LIB_WINDOWS_DLL_NAME = 1000
,
DOCA_APSH_LIB_WINDOWS_SIZE_OF_IMAGE = 1001
, DOCA_APSH_LIB_LINUX_LOAD_ADRESS = 2000
} |
| | doca app shield lib attributes More...
|
| |
| enum | doca_apsh_vad_attr {
DOCA_APSH_VMA_PID = 0
, DOCA_APSH_VMA_OFFSET = 1
, DOCA_APSH_VMA_PROTECTION = 2
, DOCA_APSH_VMA_VM_START = 3
,
DOCA_APSH_VMA_VM_END = 4
, DOCA_APSH_VMA_PROCESS_NAME = 5
, DOCA_APSH_VMA_FILE_PATH = 6
, DOCA_APSH_VMA_WINDOWS_COMMIT_CHARGE = 1000
,
DOCA_APSH_VMA_WINDOWS_PRIVATE_MEMORY = 1001
, DOCA_APSH_VMA_WINDOWS_TAG = 1002
} |
| | doca app shield virtual address descriptor attributes More...
|
| |
| enum | doca_apsh_attestation_attr {
DOCA_APSH_ATTESTATION_PID = 0
, DOCA_APSH_ATTESTATION_COMM = 1
, DOCA_APSH_ATTESTATION_PATH_OF_MEMORY_AREA = 2
, DOCA_APSH_ATTESTATION_PROTECTION = 3
,
DOCA_APSH_ATTESTATION_START_ADDRESS = 4
, DOCA_APSH_ATTESTATION_END_ADDRESS = 5
, DOCA_APSH_ATTESTATION_PAGES_NUMBER = 6
, DOCA_APSH_ATTESTATION_PAGES_PRESENT = 7
,
DOCA_APSH_ATTESTATION_MATCHING_HASHES = 8
, DOCA_APSH_ATTESTATION_HASH_DATA_IS_PRESENT = 9
} |
| | doca app shield attestation attributes More...
|
| |
| enum | doca_apsh_module_attr { DOCA_APSH_MODULES_OFFSET = 0
, DOCA_APSH_MODULES_NAME = 1
, DOCA_APSH_MODULES_SIZE = 2
} |
| | doca app shield module attributes More...
|
| |
| enum | doca_apsh_privilege_attr {
DOCA_APSH_PRIVILEGES_PID = 0
, DOCA_APSH_PRIVILEGES_NAME = 2
, DOCA_APSH_PRIVILEGES_IS_ON = 3
, DOCA_APSH_PRIVILEGES_WINDOWS_PRESENT = 1000
,
DOCA_APSH_PRIVILEGES_WINDOWS_ENABLED = 1001
, DOCA_APSH_PRIVILEGES_WINDOWS_DEFAULT = 1002
} |
| | doca app shield privileges attributes windows privilege list can be found on: https://docs.microsoft.com/en-us/windows/win32/secauthz/privilege-constants More...
|
| |
| enum | doca_apsh_envar_attr { DOCA_APSH_ENVARS_PID = 0
, DOCA_APSH_ENVARS_VARIABLE = 2
, DOCA_APSH_ENVARS_VALUE = 3
, DOCA_APSH_ENVARS_WINDOWS_BLOCK = 1000
} |
| | doca app shield envars attributes More...
|
| |
| enum | doca_apsh_ldrmodule_attr {
DOCA_APSH_LDRMODULE_PID = 0
, DOCA_APSH_LDRMODULE_BASE_ADDRESS = 2
, DOCA_APSH_LDRMODULE_LIBRARY_PATH = 3
, DOCA_APSH_LDRMODULE_WINDOWS_DLL_NAME = 1000
,
DOCA_APSH_LDRMODULE_WINDOWS_SIZE_OF_IMAGE = 1001
, DOCA_APSH_LDRMODULE_WINDOWS_INLOAD = 1002
, DOCA_APSH_LDRMODULE_WINDOWS_INMEM = 1003
, DOCA_APSH_LDRMODULE_WINDOWS_ININIT = 1004
} |
| | doca app shield LDR-Modules attributes More...
|
| |
| enum | doca_apsh_handle_attr {
DOCA_APSH_HANDLE_PID = 0
, DOCA_APSH_HANDLE_VALUE = 2
, DOCA_APSH_HANDLE_TABLE_ENTRY = 3
, DOCA_APSH_HANDLE_TYPE = 4
,
DOCA_APSH_HANDLE_ACCESS = 5
, DOCA_APSH_HANDLE_NAME = 6
} |
| | doca app shield handle attributes More...
|
| |
| enum | doca_apsh_process_parameters_attr { DOCA_APSH_PROCESS_PARAMETERS_PID = 0
, DOCA_APSH_PROCESS_PARAMETERS_CMD_LINE = 1
, DOCA_APSH_PROCESS_PARAMETERS_IMAGE_BASE_ADDR = 2
, DOCA_APSH_PROCESS_PARAMETERS_IMAGE_FULL_PATH = 3
} |
| | doca app shield process-parameters attributes More...
|
| |
| enum | doca_apsh_sid_attr { DOCA_APSH_PROCESS_SID_PID = 0
, DOCA_APSH_PROCESS_SID_STRING = 1
, DOCA_APSH_PROCESS_SID_ATTRIBUTES = 2
} |
| | doca app shield SID (security identifiers) attributes More...
|
| |
| enum | doca_apsh_netscan_attr {
DOCA_APSH_NETSCAN_PID = 0
, DOCA_APSH_NETSCAN_COMM = 1
, DOCA_APSH_NETSCAN_PROTOCOL = 2
, DOCA_APSH_NETSCAN_LOCAL_ADDR = 3
,
DOCA_APSH_NETSCAN_REMOTE_ADDR = 4
, DOCA_APSH_NETSCAN_LOCAL_PORT = 5
, DOCA_APSH_NETSCAN_REMOTE_PORT = 6
, DOCA_APSH_NETSCAN_STATE = 7
,
DOCA_APSH_NETSCAN_TIME = 8
, DOCA_APSH_NETSCAN_WINDOWS_TIME = 1000
, DOCA_APSH_NETSCAN_LINUX_FD = 2000
, DOCA_APSH_NETSCAN_LINUX_SOCKET_OFFSET = 2001
,
DOCA_APSH_NETSCAN_LINUX_FAMILY = 2002
, DOCA_APSH_NETSCAN_LINUX_TYPE = 2003
, DOCA_APSH_NETSCAN_LINUX_FILTER = 2004
, DOCA_APSH_NETSCAN_LINUX_NET_NAMESPACE = 2005
,
DOCA_APSH_NETSCAN_LINUX_TCP_BYTES_SENT = 2006
, DOCA_APSH_NETSCAN_LINUX_TCP_BYTES_ACKED = 2007
, DOCA_APSH_NETSCAN_LINUX_TCP_BYTES_RECEIVED = 2008
, DOCA_APSH_NETSCAN_LINUX_TCP_SEGS_IN = 2009
,
DOCA_APSH_NETSCAN_LINUX_TCP_SEGS_OUT = 2010
, DOCA_APSH_NETSCAN_LINUX_TCP_DATA_SEGS_IN = 2011
, DOCA_APSH_NETSCAN_LINUX_TCP_DATA_SEGS_OUT = 2012
, DOCA_APSH_NETSCAN_LINUX_INTERFACE_NAME = 2013
,
DOCA_APSH_NETSCAN_LINUX_INTERFACE_IPV4_ARR = 2014
, DOCA_APSH_NETSCAN_LINUX_INTERFACE_IPV4_ARR_SIZE = 2015
, DOCA_APSH_NETSCAN_LINUX_INTERFACE_MAC_ARR = 2016
, DOCA_APSH_NETSCAN_LINUX_INTERFACE_MAC_ARR_SIZE = 2017
,
DOCA_APSH_NETSCAN_LINUX_INTERFACE_IPV6_ARR = 2018
, DOCA_APSH_NETSCAN_LINUX_INTERFACE_IPV6_ARR_SIZE = 2019
} |
| | doca app shield netscan attributes More...
|
| |
| enum | doca_apsh_interface_attr {
DOCA_APSH_LINUX_INTERFACE_NAME = 3000
, DOCA_APSH_LINUX_INTERFACE_IPV4_ARR = 3001
, DOCA_APSH_LINUX_INTERFACE_IPV4_PREFIX_LEN_ARR = 3002
, DOCA_APSH_LINUX_INTERFACE_IPV4_ARR_SIZE = 3003
,
DOCA_APSH_LINUX_INTERFACE_MAC_ARR = 3004
, DOCA_APSH_LINUX_INTERFACE_MAC_ARR_SIZE = 3005
, DOCA_APSH_LINUX_INTERFACE_IPV6_ARR = 3006
, DOCA_APSH_LINUX_INTERFACE_IPV6_PREFIX_LEN_ARR = 3007
,
DOCA_APSH_LINUX_INTERFACE_IPV6_ARR_SIZE = 3008
, DOCA_APSH_LINUX_INTERFACE_NAMESPACE = 3009
} |
| | doca app shield interface attributes More...
|
| |
| enum | doca_apsh_yara_rule { DOCA_APSH_YARA_RULE_HELLO_WORLD = 0
, DOCA_APSH_YARA_RULE_REFLECTIVE_DLL_INJECTION = 1
, DOCA_APSH_YARA_RULE_MIMIKATZ = 2
} |
| | available doca app shield yara rules More...
|
| |
| enum | doca_apsh_yara_scan_type { DOCA_APSH_YARA_SCAN_VMA = 1
, DOCA_APSH_YARA_SCAN_HEAP = 1 << 1
} |
| | doca app shield yara scan type bitmask More...
|
| |
| enum | doca_apsh_yara_attr {
DOCA_APSH_YARA_PID = 0
, DOCA_APSH_YARA_COMM = 1
, DOCA_APSH_YARA_RULE = 2
, DOCA_APSH_YARA_MATCH_WINDOW_ADDR = 3
,
DOCA_APSH_YARA_MATCH_WINDOW_LEN = 4
} |
| | doca app shield yara attributes More...
|
| |
| enum | doca_apsh_injection_detect_attr {
DOCA_APSH_INJECTION_DETECT_PID
, DOCA_APSH_INJECTION_DETECT_VAD_START
, DOCA_APSH_INJECTION_DETECT_VAD_END
, DOCA_APSH_INJECTION_DETECT_VAD_PROTECTION
,
DOCA_APSH_INJECTION_DETECT_VAD_TAG
, DOCA_APSH_INJECTION_DETECT_VAD_FILE_PATH
, DOCA_APSH_INJECTION_DETECT_SUSPECTED_AREA_START
, DOCA_APSH_INJECTION_DETECT_SUSPECTED_AREA_END
} |
| | doca app shield injection detect attributes More...
|
| |
| enum | doca_apsh_container_attr { DOCA_APSH_CONTAINER_ID = 0
} |
| | doca app shield process attributes More...
|
| |
| enum | doca_apsh_proc_file_details_attr {
DOCA_APSH_PROCESS_FILE_DETAILS_PID = 0
, DOCA_APSH_PROCESS_FILE_DETAILS_PATH = 1
, DOCA_APSH_PROCESS_FILE_DETAILS_SHA1 = 2
, DOCA_APSH_PROCESS_FILE_DETAILS_SHA256 = 3
,
DOCA_APSH_PROCESS_FILE_DETAILS_INODE = 4
, DOCA_APSH_PROCESS_FILE_DETAILS_SIZE = 5
, DOCA_APSH_PROCESS_FILE_DETAILS_ELF_TYPE = 6
, DOCA_APSH_PROCESS_FILE_DETAILS_INODE_ADDRESS = 7
} |
| | doca app shield process file details attributes More...
|
| |