Module: EndpointSecurity::EventType

Defined in:
lib/endpoint_security/generated/event_types.rb

Overview

Event names and numeric values from the build SDK.

Constant Summary collapse

AUTH_EXEC =

The auth_exec event.

:auth_exec
AUTH_OPEN =

The auth_open event.

:auth_open
AUTH_KEXTLOAD =

The auth_kextload event.

:auth_kextload
AUTH_MMAP =

The auth_mmap event.

:auth_mmap
AUTH_MPROTECT =

The auth_mprotect event.

:auth_mprotect
AUTH_MOUNT =

The auth_mount event.

:auth_mount
AUTH_RENAME =

The auth_rename event.

:auth_rename
AUTH_SIGNAL =

The auth_signal event.

:auth_signal
:auth_unlink
NOTIFY_EXEC =

The notify_exec event.

:notify_exec
NOTIFY_OPEN =

The notify_open event.

:notify_open
NOTIFY_FORK =

The notify_fork event.

:notify_fork
NOTIFY_CLOSE =

The notify_close event.

:notify_close
NOTIFY_CREATE =

The notify_create event.

:notify_create
NOTIFY_EXCHANGEDATA =

The notify_exchangedata event.

:notify_exchangedata
NOTIFY_EXIT =

The notify_exit event.

:notify_exit
NOTIFY_GET_TASK =

The notify_get_task event.

:notify_get_task
NOTIFY_KEXTLOAD =

The notify_kextload event.

:notify_kextload
NOTIFY_KEXTUNLOAD =

The notify_kextunload event.

:notify_kextunload
:notify_link
NOTIFY_MMAP =

The notify_mmap event.

:notify_mmap
NOTIFY_MPROTECT =

The notify_mprotect event.

:notify_mprotect
NOTIFY_MOUNT =

The notify_mount event.

:notify_mount
NOTIFY_UNMOUNT =

The notify_unmount event.

:notify_unmount
NOTIFY_IOKIT_OPEN =

The notify_iokit_open event.

:notify_iokit_open
NOTIFY_RENAME =

The notify_rename event.

:notify_rename
NOTIFY_SETATTRLIST =

The notify_setattrlist event.

:notify_setattrlist
NOTIFY_SETEXTATTR =

The notify_setextattr event.

:notify_setextattr
NOTIFY_SETFLAGS =

The notify_setflags event.

:notify_setflags
NOTIFY_SETMODE =

The notify_setmode event.

:notify_setmode
NOTIFY_SETOWNER =

The notify_setowner event.

:notify_setowner
NOTIFY_SIGNAL =

The notify_signal event.

:notify_signal
:notify_unlink
NOTIFY_WRITE =

The notify_write event.

:notify_write
AUTH_FILE_PROVIDER_MATERIALIZE =

The auth_file_provider_materialize event.

:auth_file_provider_materialize
NOTIFY_FILE_PROVIDER_MATERIALIZE =

The notify_file_provider_materialize event.

:notify_file_provider_materialize
AUTH_FILE_PROVIDER_UPDATE =

The auth_file_provider_update event.

:auth_file_provider_update
NOTIFY_FILE_PROVIDER_UPDATE =

The notify_file_provider_update event.

:notify_file_provider_update
:auth_readlink
:notify_readlink
AUTH_TRUNCATE =

The auth_truncate event.

:auth_truncate
NOTIFY_TRUNCATE =

The notify_truncate event.

:notify_truncate
:auth_link
NOTIFY_LOOKUP =

The notify_lookup event.

:notify_lookup
AUTH_CREATE =

The auth_create event.

:auth_create
AUTH_SETATTRLIST =

The auth_setattrlist event.

:auth_setattrlist
AUTH_SETEXTATTR =

The auth_setextattr event.

:auth_setextattr
AUTH_SETFLAGS =

The auth_setflags event.

:auth_setflags
AUTH_SETMODE =

The auth_setmode event.

:auth_setmode
AUTH_SETOWNER =

The auth_setowner event.

:auth_setowner
AUTH_CHDIR =

The auth_chdir event.

:auth_chdir
NOTIFY_CHDIR =

The notify_chdir event.

:notify_chdir
AUTH_GETATTRLIST =

The auth_getattrlist event.

:auth_getattrlist
NOTIFY_GETATTRLIST =

The notify_getattrlist event.

:notify_getattrlist
NOTIFY_STAT =

The notify_stat event.

:notify_stat
NOTIFY_ACCESS =

The notify_access event.

:notify_access
AUTH_CHROOT =

The auth_chroot event.

:auth_chroot
NOTIFY_CHROOT =

The notify_chroot event.

:notify_chroot
AUTH_UTIMES =

The auth_utimes event.

:auth_utimes
NOTIFY_UTIMES =

The notify_utimes event.

:notify_utimes
AUTH_CLONE =

The auth_clone event.

:auth_clone
NOTIFY_CLONE =

The notify_clone event.

:notify_clone
NOTIFY_FCNTL =

The notify_fcntl event.

:notify_fcntl
AUTH_GETEXTATTR =

The auth_getextattr event.

:auth_getextattr
NOTIFY_GETEXTATTR =

The notify_getextattr event.

:notify_getextattr
AUTH_LISTEXTATTR =

The auth_listextattr event.

:auth_listextattr
NOTIFY_LISTEXTATTR =

The notify_listextattr event.

:notify_listextattr
AUTH_READDIR =

The auth_readdir event.

:auth_readdir
NOTIFY_READDIR =

The notify_readdir event.

:notify_readdir
AUTH_DELETEEXTATTR =

The auth_deleteextattr event.

:auth_deleteextattr
NOTIFY_DELETEEXTATTR =

The notify_deleteextattr event.

:notify_deleteextattr
AUTH_FSGETPATH =

The auth_fsgetpath event.

:auth_fsgetpath
NOTIFY_FSGETPATH =

The notify_fsgetpath event.

:notify_fsgetpath
NOTIFY_DUP =

The notify_dup event.

:notify_dup
AUTH_SETTIME =

The auth_settime event.

:auth_settime
NOTIFY_SETTIME =

The notify_settime event.

:notify_settime
NOTIFY_UIPC_BIND =

The notify_uipc_bind event.

:notify_uipc_bind
AUTH_UIPC_BIND =

The auth_uipc_bind event.

:auth_uipc_bind
NOTIFY_UIPC_CONNECT =

The notify_uipc_connect event.

:notify_uipc_connect
AUTH_UIPC_CONNECT =

The auth_uipc_connect event.

:auth_uipc_connect
AUTH_EXCHANGEDATA =

The auth_exchangedata event.

:auth_exchangedata
AUTH_SETACL =

The auth_setacl event.

:auth_setacl
NOTIFY_SETACL =

The notify_setacl event.

:notify_setacl
NOTIFY_PTY_GRANT =

The notify_pty_grant event.

:notify_pty_grant
NOTIFY_PTY_CLOSE =

The notify_pty_close event.

:notify_pty_close
AUTH_PROC_CHECK =

The auth_proc_check event.

:auth_proc_check
NOTIFY_PROC_CHECK =

The notify_proc_check event.

:notify_proc_check
AUTH_GET_TASK =

The auth_get_task event.

:auth_get_task
AUTH_SEARCHFS =

The auth_searchfs event.

:auth_searchfs
NOTIFY_SEARCHFS =

The notify_searchfs event.

:notify_searchfs
AUTH_FCNTL =

The auth_fcntl event.

:auth_fcntl
AUTH_IOKIT_OPEN =

The auth_iokit_open event.

:auth_iokit_open
AUTH_PROC_SUSPEND_RESUME =

The auth_proc_suspend_resume event.

:auth_proc_suspend_resume
NOTIFY_PROC_SUSPEND_RESUME =

The notify_proc_suspend_resume event.

:notify_proc_suspend_resume
NOTIFY_CS_INVALIDATED =

The notify_cs_invalidated event.

:notify_cs_invalidated
NOTIFY_GET_TASK_NAME =

The notify_get_task_name event.

:notify_get_task_name
NOTIFY_TRACE =

The notify_trace event.

:notify_trace
NOTIFY_REMOTE_THREAD_CREATE =

The notify_remote_thread_create event.

:notify_remote_thread_create
AUTH_REMOUNT =

The auth_remount event.

:auth_remount
NOTIFY_REMOUNT =

The notify_remount event.

:notify_remount
AUTH_GET_TASK_READ =

The auth_get_task_read event.

:auth_get_task_read
NOTIFY_GET_TASK_READ =

The notify_get_task_read event.

:notify_get_task_read
NOTIFY_GET_TASK_INSPECT =

The notify_get_task_inspect event.

:notify_get_task_inspect
NOTIFY_SETUID =

The notify_setuid event.

:notify_setuid
NOTIFY_SETGID =

The notify_setgid event.

:notify_setgid
NOTIFY_SETEUID =

The notify_seteuid event.

:notify_seteuid
NOTIFY_SETEGID =

The notify_setegid event.

:notify_setegid
NOTIFY_SETREUID =

The notify_setreuid event.

:notify_setreuid
NOTIFY_SETREGID =

The notify_setregid event.

:notify_setregid
AUTH_COPYFILE =

The auth_copyfile event.

:auth_copyfile
NOTIFY_COPYFILE =

The notify_copyfile event.

:notify_copyfile
NOTIFY_AUTHENTICATION =

The notify_authentication event.

:notify_authentication
NOTIFY_XP_MALWARE_DETECTED =

The notify_xp_malware_detected event.

:notify_xp_malware_detected
NOTIFY_XP_MALWARE_REMEDIATED =

The notify_xp_malware_remediated event.

:notify_xp_malware_remediated
NOTIFY_LW_SESSION_LOGIN =

The notify_lw_session_login event.

:notify_lw_session_login
NOTIFY_LW_SESSION_LOGOUT =

The notify_lw_session_logout event.

:notify_lw_session_logout
NOTIFY_LW_SESSION_LOCK =

The notify_lw_session_lock event.

:notify_lw_session_lock
NOTIFY_LW_SESSION_UNLOCK =

The notify_lw_session_unlock event.

:notify_lw_session_unlock
NOTIFY_SCREENSHARING_ATTACH =

The notify_screensharing_attach event.

:notify_screensharing_attach
NOTIFY_SCREENSHARING_DETACH =

The notify_screensharing_detach event.

:notify_screensharing_detach
NOTIFY_OPENSSH_LOGIN =

The notify_openssh_login event.

:notify_openssh_login
NOTIFY_OPENSSH_LOGOUT =

The notify_openssh_logout event.

:notify_openssh_logout
NOTIFY_LOGIN_LOGIN =

The notify_login_login event.

:notify_login_login
NOTIFY_LOGIN_LOGOUT =

The notify_login_logout event.

:notify_login_logout
NOTIFY_BTM_LAUNCH_ITEM_ADD =

The notify_btm_launch_item_add event.

:notify_btm_launch_item_add
NOTIFY_BTM_LAUNCH_ITEM_REMOVE =

The notify_btm_launch_item_remove event.

:notify_btm_launch_item_remove
NOTIFY_PROFILE_ADD =

The notify_profile_add event.

:notify_profile_add
NOTIFY_PROFILE_REMOVE =

The notify_profile_remove event.

:notify_profile_remove
NOTIFY_SU =

The notify_su event.

:notify_su
NOTIFY_AUTHORIZATION_PETITION =

The notify_authorization_petition event.

:notify_authorization_petition
NOTIFY_AUTHORIZATION_JUDGEMENT =

The notify_authorization_judgement event.

:notify_authorization_judgement
NOTIFY_SUDO =

The notify_sudo event.

:notify_sudo
NOTIFY_OD_GROUP_ADD =

The notify_od_group_add event.

:notify_od_group_add
NOTIFY_OD_GROUP_REMOVE =

The notify_od_group_remove event.

:notify_od_group_remove
NOTIFY_OD_GROUP_SET =

The notify_od_group_set event.

:notify_od_group_set
NOTIFY_OD_MODIFY_PASSWORD =

The notify_od_modify_password event.

:notify_od_modify_password
NOTIFY_OD_DISABLE_USER =

The notify_od_disable_user event.

:notify_od_disable_user
NOTIFY_OD_ENABLE_USER =

The notify_od_enable_user event.

:notify_od_enable_user
NOTIFY_OD_ATTRIBUTE_VALUE_ADD =

The notify_od_attribute_value_add event.

:notify_od_attribute_value_add
NOTIFY_OD_ATTRIBUTE_VALUE_REMOVE =

The notify_od_attribute_value_remove event.

:notify_od_attribute_value_remove
NOTIFY_OD_ATTRIBUTE_SET =

The notify_od_attribute_set event.

:notify_od_attribute_set
NOTIFY_OD_CREATE_USER =

The notify_od_create_user event.

:notify_od_create_user
NOTIFY_OD_CREATE_GROUP =

The notify_od_create_group event.

:notify_od_create_group
NOTIFY_OD_DELETE_USER =

The notify_od_delete_user event.

:notify_od_delete_user
NOTIFY_OD_DELETE_GROUP =

The notify_od_delete_group event.

:notify_od_delete_group
NOTIFY_XPC_CONNECT =

The notify_xpc_connect event.

:notify_xpc_connect
NOTIFY_GATEKEEPER_USER_OVERRIDE =

The notify_gatekeeper_user_override event.

:notify_gatekeeper_user_override
NOTIFY_TCC_MODIFY =

The notify_tcc_modify event.

:notify_tcc_modify
RESERVED_0 =

The reserved_0 event.

:reserved_0
RESERVED_1 =

The reserved_1 event.

:reserved_1
RESERVED_2 =

The reserved_2 event.

:reserved_2
RESERVED_3 =

The reserved_3 event.

:reserved_3
RESERVED_4 =

The reserved_4 event.

:reserved_4
RESERVED_5 =

The reserved_5 event.

:reserved_5
RESERVED_6 =

The reserved_6 event.

:reserved_6
RESERVED_7 =

The reserved_7 event.

:reserved_7
RESERVED_8 =

The reserved_8 event.

:reserved_8
LAST =

Exclusive upper bound for event enum values.

157
SYMBOL_TO_VALUE =

Event symbols keyed by their SDK enum values.

{
  auth_exec: 0,
  auth_open: 1,
  auth_kextload: 2,
  auth_mmap: 3,
  auth_mprotect: 4,
  auth_mount: 5,
  auth_rename: 6,
  auth_signal: 7,
  auth_unlink: 8,
  notify_exec: 9,
  notify_open: 10,
  notify_fork: 11,
  notify_close: 12,
  notify_create: 13,
  notify_exchangedata: 14,
  notify_exit: 15,
  notify_get_task: 16,
  notify_kextload: 17,
  notify_kextunload: 18,
  notify_link: 19,
  notify_mmap: 20,
  notify_mprotect: 21,
  notify_mount: 22,
  notify_unmount: 23,
  notify_iokit_open: 24,
  notify_rename: 25,
  notify_setattrlist: 26,
  notify_setextattr: 27,
  notify_setflags: 28,
  notify_setmode: 29,
  notify_setowner: 30,
  notify_signal: 31,
  notify_unlink: 32,
  notify_write: 33,
  auth_file_provider_materialize: 34,
  notify_file_provider_materialize: 35,
  auth_file_provider_update: 36,
  notify_file_provider_update: 37,
  auth_readlink: 38,
  notify_readlink: 39,
  auth_truncate: 40,
  notify_truncate: 41,
  auth_link: 42,
  notify_lookup: 43,
  auth_create: 44,
  auth_setattrlist: 45,
  auth_setextattr: 46,
  auth_setflags: 47,
  auth_setmode: 48,
  auth_setowner: 49,
  auth_chdir: 50,
  notify_chdir: 51,
  auth_getattrlist: 52,
  notify_getattrlist: 53,
  notify_stat: 54,
  notify_access: 55,
  auth_chroot: 56,
  notify_chroot: 57,
  auth_utimes: 58,
  notify_utimes: 59,
  auth_clone: 60,
  notify_clone: 61,
  notify_fcntl: 62,
  auth_getextattr: 63,
  notify_getextattr: 64,
  auth_listextattr: 65,
  notify_listextattr: 66,
  auth_readdir: 67,
  notify_readdir: 68,
  auth_deleteextattr: 69,
  notify_deleteextattr: 70,
  auth_fsgetpath: 71,
  notify_fsgetpath: 72,
  notify_dup: 73,
  auth_settime: 74,
  notify_settime: 75,
  notify_uipc_bind: 76,
  auth_uipc_bind: 77,
  notify_uipc_connect: 78,
  auth_uipc_connect: 79,
  auth_exchangedata: 80,
  auth_setacl: 81,
  notify_setacl: 82,
  notify_pty_grant: 83,
  notify_pty_close: 84,
  auth_proc_check: 85,
  notify_proc_check: 86,
  auth_get_task: 87,
  auth_searchfs: 88,
  notify_searchfs: 89,
  auth_fcntl: 90,
  auth_iokit_open: 91,
  auth_proc_suspend_resume: 92,
  notify_proc_suspend_resume: 93,
  notify_cs_invalidated: 94,
  notify_get_task_name: 95,
  notify_trace: 96,
  notify_remote_thread_create: 97,
  auth_remount: 98,
  notify_remount: 99,
  auth_get_task_read: 100,
  notify_get_task_read: 101,
  notify_get_task_inspect: 102,
  notify_setuid: 103,
  notify_setgid: 104,
  notify_seteuid: 105,
  notify_setegid: 106,
  notify_setreuid: 107,
  notify_setregid: 108,
  auth_copyfile: 109,
  notify_copyfile: 110,
  notify_authentication: 111,
  notify_xp_malware_detected: 112,
  notify_xp_malware_remediated: 113,
  notify_lw_session_login: 114,
  notify_lw_session_logout: 115,
  notify_lw_session_lock: 116,
  notify_lw_session_unlock: 117,
  notify_screensharing_attach: 118,
  notify_screensharing_detach: 119,
  notify_openssh_login: 120,
  notify_openssh_logout: 121,
  notify_login_login: 122,
  notify_login_logout: 123,
  notify_btm_launch_item_add: 124,
  notify_btm_launch_item_remove: 125,
  notify_profile_add: 126,
  notify_profile_remove: 127,
  notify_su: 128,
  notify_authorization_petition: 129,
  notify_authorization_judgement: 130,
  notify_sudo: 131,
  notify_od_group_add: 132,
  notify_od_group_remove: 133,
  notify_od_group_set: 134,
  notify_od_modify_password: 135,
  notify_od_disable_user: 136,
  notify_od_enable_user: 137,
  notify_od_attribute_value_add: 138,
  notify_od_attribute_value_remove: 139,
  notify_od_attribute_set: 140,
  notify_od_create_user: 141,
  notify_od_create_group: 142,
  notify_od_delete_user: 143,
  notify_od_delete_group: 144,
  notify_xpc_connect: 145,
  notify_gatekeeper_user_override: 146,
  notify_tcc_modify: 147,
  reserved_0: 148,
  reserved_1: 149,
  reserved_2: 150,
  reserved_3: 151,
  reserved_4: 152,
  reserved_5: 153,
  reserved_6: 154,
  reserved_7: 155,
  reserved_8: 156
}.freeze
VALUE_TO_SYMBOL =

SDK enum values keyed by event symbol.

SYMBOL_TO_VALUE.invert.freeze
ALL =

All events known to the build SDK.

SYMBOL_TO_VALUE.keys.freeze
ALL_AUTH =

All authorization events.

ALL.select { |event| event.to_s.start_with?("auth_") }.freeze
ALL_NOTIFY =

All notification events.

ALL.select { |event| event.to_s.start_with?("notify_") }.freeze
RESERVED =

Undocumented reserved event slots.

[:reserved_0, :reserved_1, :reserved_2, :reserved_3, :reserved_4, :reserved_5, :reserved_6, :reserved_7, :reserved_8].freeze
CACHEABLE =

Events for which Endpoint Security accepts cached responses.

[:auth_exec, :auth_open, :auth_mmap, :auth_mount, :auth_setflags, :auth_setmode, :auth_setowner, :auth_chdir, :auth_getattrlist, :auth_chroot, :auth_utimes, :auth_getextattr, :auth_listextattr, :auth_readdir, :auth_fsgetpath, :auth_uipc_connect, :auth_proc_check, :auth_get_task, :auth_searchfs, :auth_get_task_read].freeze

Class Method Summary collapse

Class Method Details

.all ⇒ Array<Symbol>

Returns all events.

Returns:

  • (Array<Symbol>) —

    all events



500
501
# File 'lib/endpoint_security/generated/event_types.rb', line 500

def all = ALL
# @return [Array<Symbol>] authorization events

.all_auth ⇒ Array<Symbol>

Returns authorization events.

Returns:

  • (Array<Symbol>) —

    authorization events



502
503
# File 'lib/endpoint_security/generated/event_types.rb', line 502

def all_auth = ALL_AUTH
# @return [Array<Symbol>] notification events

.all_notify ⇒ Array<Symbol>

Returns notification events.

Returns:

  • (Array<Symbol>) —

    notification events



504
505
# File 'lib/endpoint_security/generated/event_types.rb', line 504

def all_notify = ALL_NOTIFY
# @return [Boolean] whether +event+ is an authorization event

.auth?(event) ⇒ Boolean

Returns whether event is an authorization event.

Returns:

  • (Boolean) —

    whether event is an authorization event



506
507
# File 'lib/endpoint_security/generated/event_types.rb', line 506

def auth?(event) = event.to_s.start_with?("auth_")
# @return [Boolean] whether +event+ is a notification event

.cacheable?(event) ⇒ Boolean

Returns whether event accepts a cached response.

Returns:

  • (Boolean) —

    whether event accepts a cached response



512
513
# File 'lib/endpoint_security/generated/event_types.rb', line 512

def cacheable?(event) = CACHEABLE.include?(event.to_sym)
# @return [Boolean] whether +event+ uses a flags response

.flags_response?(event) ⇒ Boolean

Returns whether event uses a flags response.

Returns:

  • (Boolean) —

    whether event uses a flags response



514
515
# File 'lib/endpoint_security/generated/event_types.rb', line 514

def flags_response?(event) = event.to_sym == :auth_open
# @return [Integer] SDK enum value for +event+

.notify?(event) ⇒ Boolean

Returns whether event is a notification event.

Returns:

  • (Boolean) —

    whether event is a notification event



508
509
# File 'lib/endpoint_security/generated/event_types.rb', line 508

def notify?(event) = event.to_s.start_with?("notify_")
# @return [Boolean] whether +event+ is an undocumented reserved slot

.reserved?(event) ⇒ Boolean

Returns whether event is an undocumented reserved slot.

Returns:

  • (Boolean) —

    whether event is an undocumented reserved slot



510
511
# File 'lib/endpoint_security/generated/event_types.rb', line 510

def reserved?(event) = RESERVED.include?(event.to_sym)
# @return [Boolean] whether +event+ accepts a cached response

.symbol(value) ⇒ Symbol, Integer

Returns event symbol, or value when unknown.

Returns:

  • (Symbol, Integer) —

    event symbol, or value when unknown



518
# File 'lib/endpoint_security/generated/event_types.rb', line 518

def symbol(value) = VALUE_TO_SYMBOL.fetch(value, value)

.value(event) ⇒ Integer

Returns SDK enum value for event.

Returns:

  • (Integer) —

    SDK enum value for event



516
517
# File 'lib/endpoint_security/generated/event_types.rb', line 516

def value(event) = SYMBOL_TO_VALUE.fetch(event.to_sym)
# @return [Symbol, Integer] event symbol, or +value+ when unknown