Module: EndpointSecurity::EventType
- Defined in:
- lib/endpoint_security/generated/event_types.rb
Overview
Event names and numeric values from the build SDK.
Constant Summary collapse
- AUTH_EXEC =
The
auth_execevent. :auth_exec- AUTH_OPEN =
The
auth_openevent. :auth_open- AUTH_KEXTLOAD =
The
auth_kextloadevent. :auth_kextload- AUTH_MMAP =
The
auth_mmapevent. :auth_mmap- AUTH_MPROTECT =
The
auth_mprotectevent. :auth_mprotect- AUTH_MOUNT =
The
auth_mountevent. :auth_mount- AUTH_RENAME =
The
auth_renameevent. :auth_rename- AUTH_SIGNAL =
The
auth_signalevent. :auth_signal- AUTH_UNLINK =
The
auth_unlinkevent. :auth_unlink- NOTIFY_EXEC =
The
notify_execevent. :notify_exec- NOTIFY_OPEN =
The
notify_openevent. :notify_open- NOTIFY_FORK =
The
notify_forkevent. :notify_fork- NOTIFY_CLOSE =
The
notify_closeevent. :notify_close- NOTIFY_CREATE =
The
notify_createevent. :notify_create- NOTIFY_EXCHANGEDATA =
The
notify_exchangedataevent. :notify_exchangedata- NOTIFY_EXIT =
The
notify_exitevent. :notify_exit- NOTIFY_GET_TASK =
The
notify_get_taskevent. :notify_get_task- NOTIFY_KEXTLOAD =
The
notify_kextloadevent. :notify_kextload- NOTIFY_KEXTUNLOAD =
The
notify_kextunloadevent. :notify_kextunload- NOTIFY_LINK =
The
notify_linkevent. :notify_link- NOTIFY_MMAP =
The
notify_mmapevent. :notify_mmap- NOTIFY_MPROTECT =
The
notify_mprotectevent. :notify_mprotect- NOTIFY_MOUNT =
The
notify_mountevent. :notify_mount- NOTIFY_UNMOUNT =
The
notify_unmountevent. :notify_unmount- NOTIFY_IOKIT_OPEN =
The
notify_iokit_openevent. :notify_iokit_open- NOTIFY_RENAME =
The
notify_renameevent. :notify_rename- NOTIFY_SETATTRLIST =
The
notify_setattrlistevent. :notify_setattrlist- NOTIFY_SETEXTATTR =
The
notify_setextattrevent. :notify_setextattr- NOTIFY_SETFLAGS =
The
notify_setflagsevent. :notify_setflags- NOTIFY_SETMODE =
The
notify_setmodeevent. :notify_setmode- NOTIFY_SETOWNER =
The
notify_setownerevent. :notify_setowner- NOTIFY_SIGNAL =
The
notify_signalevent. :notify_signal- NOTIFY_UNLINK =
The
notify_unlinkevent. :notify_unlink- NOTIFY_WRITE =
The
notify_writeevent. :notify_write- AUTH_FILE_PROVIDER_MATERIALIZE =
The
auth_file_provider_materializeevent. :auth_file_provider_materialize- NOTIFY_FILE_PROVIDER_MATERIALIZE =
The
notify_file_provider_materializeevent. :notify_file_provider_materialize- AUTH_FILE_PROVIDER_UPDATE =
The
auth_file_provider_updateevent. :auth_file_provider_update- NOTIFY_FILE_PROVIDER_UPDATE =
The
notify_file_provider_updateevent. :notify_file_provider_update- AUTH_READLINK =
The
auth_readlinkevent. :auth_readlink- NOTIFY_READLINK =
The
notify_readlinkevent. :notify_readlink- AUTH_TRUNCATE =
The
auth_truncateevent. :auth_truncate- NOTIFY_TRUNCATE =
The
notify_truncateevent. :notify_truncate- AUTH_LINK =
The
auth_linkevent. :auth_link- NOTIFY_LOOKUP =
The
notify_lookupevent. :notify_lookup- AUTH_CREATE =
The
auth_createevent. :auth_create- AUTH_SETATTRLIST =
The
auth_setattrlistevent. :auth_setattrlist- AUTH_SETEXTATTR =
The
auth_setextattrevent. :auth_setextattr- AUTH_SETFLAGS =
The
auth_setflagsevent. :auth_setflags- AUTH_SETMODE =
The
auth_setmodeevent. :auth_setmode- AUTH_SETOWNER =
The
auth_setownerevent. :auth_setowner- AUTH_CHDIR =
The
auth_chdirevent. :auth_chdir- NOTIFY_CHDIR =
The
notify_chdirevent. :notify_chdir- AUTH_GETATTRLIST =
The
auth_getattrlistevent. :auth_getattrlist- NOTIFY_GETATTRLIST =
The
notify_getattrlistevent. :notify_getattrlist- NOTIFY_STAT =
The
notify_statevent. :notify_stat- NOTIFY_ACCESS =
The
notify_accessevent. :notify_access- AUTH_CHROOT =
The
auth_chrootevent. :auth_chroot- NOTIFY_CHROOT =
The
notify_chrootevent. :notify_chroot- AUTH_UTIMES =
The
auth_utimesevent. :auth_utimes- NOTIFY_UTIMES =
The
notify_utimesevent. :notify_utimes- AUTH_CLONE =
The
auth_cloneevent. :auth_clone- NOTIFY_CLONE =
The
notify_cloneevent. :notify_clone- NOTIFY_FCNTL =
The
notify_fcntlevent. :notify_fcntl- AUTH_GETEXTATTR =
The
auth_getextattrevent. :auth_getextattr- NOTIFY_GETEXTATTR =
The
notify_getextattrevent. :notify_getextattr- AUTH_LISTEXTATTR =
The
auth_listextattrevent. :auth_listextattr- NOTIFY_LISTEXTATTR =
The
notify_listextattrevent. :notify_listextattr- AUTH_READDIR =
The
auth_readdirevent. :auth_readdir- NOTIFY_READDIR =
The
notify_readdirevent. :notify_readdir- AUTH_DELETEEXTATTR =
The
auth_deleteextattrevent. :auth_deleteextattr- NOTIFY_DELETEEXTATTR =
The
notify_deleteextattrevent. :notify_deleteextattr- AUTH_FSGETPATH =
The
auth_fsgetpathevent. :auth_fsgetpath- NOTIFY_FSGETPATH =
The
notify_fsgetpathevent. :notify_fsgetpath- NOTIFY_DUP =
The
notify_dupevent. :notify_dup- AUTH_SETTIME =
The
auth_settimeevent. :auth_settime- NOTIFY_SETTIME =
The
notify_settimeevent. :notify_settime- NOTIFY_UIPC_BIND =
The
notify_uipc_bindevent. :notify_uipc_bind- AUTH_UIPC_BIND =
The
auth_uipc_bindevent. :auth_uipc_bind- NOTIFY_UIPC_CONNECT =
The
notify_uipc_connectevent. :notify_uipc_connect- AUTH_UIPC_CONNECT =
The
auth_uipc_connectevent. :auth_uipc_connect- AUTH_EXCHANGEDATA =
The
auth_exchangedataevent. :auth_exchangedata- AUTH_SETACL =
The
auth_setaclevent. :auth_setacl- NOTIFY_SETACL =
The
notify_setaclevent. :notify_setacl- NOTIFY_PTY_GRANT =
The
notify_pty_grantevent. :notify_pty_grant- NOTIFY_PTY_CLOSE =
The
notify_pty_closeevent. :notify_pty_close- AUTH_PROC_CHECK =
The
auth_proc_checkevent. :auth_proc_check- NOTIFY_PROC_CHECK =
The
notify_proc_checkevent. :notify_proc_check- AUTH_GET_TASK =
The
auth_get_taskevent. :auth_get_task- AUTH_SEARCHFS =
The
auth_searchfsevent. :auth_searchfs- NOTIFY_SEARCHFS =
The
notify_searchfsevent. :notify_searchfs- AUTH_FCNTL =
The
auth_fcntlevent. :auth_fcntl- AUTH_IOKIT_OPEN =
The
auth_iokit_openevent. :auth_iokit_open- AUTH_PROC_SUSPEND_RESUME =
The
auth_proc_suspend_resumeevent. :auth_proc_suspend_resume- NOTIFY_PROC_SUSPEND_RESUME =
The
notify_proc_suspend_resumeevent. :notify_proc_suspend_resume- NOTIFY_CS_INVALIDATED =
The
notify_cs_invalidatedevent. :notify_cs_invalidated- NOTIFY_GET_TASK_NAME =
The
notify_get_task_nameevent. :notify_get_task_name- NOTIFY_TRACE =
The
notify_traceevent. :notify_trace- NOTIFY_REMOTE_THREAD_CREATE =
The
notify_remote_thread_createevent. :notify_remote_thread_create- AUTH_REMOUNT =
The
auth_remountevent. :auth_remount- NOTIFY_REMOUNT =
The
notify_remountevent. :notify_remount- AUTH_GET_TASK_READ =
The
auth_get_task_readevent. :auth_get_task_read- NOTIFY_GET_TASK_READ =
The
notify_get_task_readevent. :notify_get_task_read- NOTIFY_GET_TASK_INSPECT =
The
notify_get_task_inspectevent. :notify_get_task_inspect- NOTIFY_SETUID =
The
notify_setuidevent. :notify_setuid- NOTIFY_SETGID =
The
notify_setgidevent. :notify_setgid- NOTIFY_SETEUID =
The
notify_seteuidevent. :notify_seteuid- NOTIFY_SETEGID =
The
notify_setegidevent. :notify_setegid- NOTIFY_SETREUID =
The
notify_setreuidevent. :notify_setreuid- NOTIFY_SETREGID =
The
notify_setregidevent. :notify_setregid- AUTH_COPYFILE =
The
auth_copyfileevent. :auth_copyfile- NOTIFY_COPYFILE =
The
notify_copyfileevent. :notify_copyfile- NOTIFY_AUTHENTICATION =
The
notify_authenticationevent. :notify_authentication- NOTIFY_XP_MALWARE_DETECTED =
The
notify_xp_malware_detectedevent. :notify_xp_malware_detected- NOTIFY_XP_MALWARE_REMEDIATED =
The
notify_xp_malware_remediatedevent. :notify_xp_malware_remediated- NOTIFY_LW_SESSION_LOGIN =
The
notify_lw_session_loginevent. :notify_lw_session_login- NOTIFY_LW_SESSION_LOGOUT =
The
notify_lw_session_logoutevent. :notify_lw_session_logout- NOTIFY_LW_SESSION_LOCK =
The
notify_lw_session_lockevent. :notify_lw_session_lock- NOTIFY_LW_SESSION_UNLOCK =
The
notify_lw_session_unlockevent. :notify_lw_session_unlock- NOTIFY_SCREENSHARING_ATTACH =
The
notify_screensharing_attachevent. :notify_screensharing_attach- NOTIFY_SCREENSHARING_DETACH =
The
notify_screensharing_detachevent. :notify_screensharing_detach- NOTIFY_OPENSSH_LOGIN =
The
notify_openssh_loginevent. :notify_openssh_login- NOTIFY_OPENSSH_LOGOUT =
The
notify_openssh_logoutevent. :notify_openssh_logout- NOTIFY_LOGIN_LOGIN =
The
notify_login_loginevent. :notify_login_login- NOTIFY_LOGIN_LOGOUT =
The
notify_login_logoutevent. :notify_login_logout- NOTIFY_BTM_LAUNCH_ITEM_ADD =
The
notify_btm_launch_item_addevent. :notify_btm_launch_item_add- NOTIFY_BTM_LAUNCH_ITEM_REMOVE =
The
notify_btm_launch_item_removeevent. :notify_btm_launch_item_remove- NOTIFY_PROFILE_ADD =
The
notify_profile_addevent. :notify_profile_add- NOTIFY_PROFILE_REMOVE =
The
notify_profile_removeevent. :notify_profile_remove- NOTIFY_SU =
The
notify_suevent. :notify_su- NOTIFY_AUTHORIZATION_PETITION =
The
notify_authorization_petitionevent. :notify_authorization_petition- NOTIFY_AUTHORIZATION_JUDGEMENT =
The
notify_authorization_judgementevent. :notify_authorization_judgement- NOTIFY_SUDO =
The
notify_sudoevent. :notify_sudo- NOTIFY_OD_GROUP_ADD =
The
notify_od_group_addevent. :notify_od_group_add- NOTIFY_OD_GROUP_REMOVE =
The
notify_od_group_removeevent. :notify_od_group_remove- NOTIFY_OD_GROUP_SET =
The
notify_od_group_setevent. :notify_od_group_set- NOTIFY_OD_MODIFY_PASSWORD =
The
notify_od_modify_passwordevent. :notify_od_modify_password- NOTIFY_OD_DISABLE_USER =
The
notify_od_disable_userevent. :notify_od_disable_user- NOTIFY_OD_ENABLE_USER =
The
notify_od_enable_userevent. :notify_od_enable_user- NOTIFY_OD_ATTRIBUTE_VALUE_ADD =
The
notify_od_attribute_value_addevent. :notify_od_attribute_value_add- NOTIFY_OD_ATTRIBUTE_VALUE_REMOVE =
The
notify_od_attribute_value_removeevent. :notify_od_attribute_value_remove- NOTIFY_OD_ATTRIBUTE_SET =
The
notify_od_attribute_setevent. :notify_od_attribute_set- NOTIFY_OD_CREATE_USER =
The
notify_od_create_userevent. :notify_od_create_user- NOTIFY_OD_CREATE_GROUP =
The
notify_od_create_groupevent. :notify_od_create_group- NOTIFY_OD_DELETE_USER =
The
notify_od_delete_userevent. :notify_od_delete_user- NOTIFY_OD_DELETE_GROUP =
The
notify_od_delete_groupevent. :notify_od_delete_group- NOTIFY_XPC_CONNECT =
The
notify_xpc_connectevent. :notify_xpc_connect- NOTIFY_GATEKEEPER_USER_OVERRIDE =
The
notify_gatekeeper_user_overrideevent. :notify_gatekeeper_user_override- NOTIFY_TCC_MODIFY =
The
notify_tcc_modifyevent. :notify_tcc_modify- RESERVED_0 =
The
reserved_0event. :reserved_0- RESERVED_1 =
The
reserved_1event. :reserved_1- RESERVED_2 =
The
reserved_2event. :reserved_2- RESERVED_3 =
The
reserved_3event. :reserved_3- RESERVED_4 =
The
reserved_4event. :reserved_4- RESERVED_5 =
The
reserved_5event. :reserved_5- RESERVED_6 =
The
reserved_6event. :reserved_6- RESERVED_7 =
The
reserved_7event. :reserved_7- RESERVED_8 =
The
reserved_8event. :reserved_8- LAST =
Exclusive upper bound for event enum values.
157- SYMBOL_TO_VALUE =
Event symbols keyed by their SDK enum values.
{ auth_exec: 0, auth_open: 1, auth_kextload: 2, auth_mmap: 3, auth_mprotect: 4, auth_mount: 5, auth_rename: 6, auth_signal: 7, auth_unlink: 8, notify_exec: 9, notify_open: 10, notify_fork: 11, notify_close: 12, notify_create: 13, notify_exchangedata: 14, notify_exit: 15, notify_get_task: 16, notify_kextload: 17, notify_kextunload: 18, notify_link: 19, notify_mmap: 20, notify_mprotect: 21, notify_mount: 22, notify_unmount: 23, notify_iokit_open: 24, notify_rename: 25, notify_setattrlist: 26, notify_setextattr: 27, notify_setflags: 28, notify_setmode: 29, notify_setowner: 30, notify_signal: 31, notify_unlink: 32, notify_write: 33, auth_file_provider_materialize: 34, notify_file_provider_materialize: 35, auth_file_provider_update: 36, notify_file_provider_update: 37, auth_readlink: 38, notify_readlink: 39, auth_truncate: 40, notify_truncate: 41, auth_link: 42, notify_lookup: 43, auth_create: 44, auth_setattrlist: 45, auth_setextattr: 46, auth_setflags: 47, auth_setmode: 48, auth_setowner: 49, auth_chdir: 50, notify_chdir: 51, auth_getattrlist: 52, notify_getattrlist: 53, notify_stat: 54, notify_access: 55, auth_chroot: 56, notify_chroot: 57, auth_utimes: 58, notify_utimes: 59, auth_clone: 60, notify_clone: 61, notify_fcntl: 62, auth_getextattr: 63, notify_getextattr: 64, auth_listextattr: 65, notify_listextattr: 66, auth_readdir: 67, notify_readdir: 68, auth_deleteextattr: 69, notify_deleteextattr: 70, auth_fsgetpath: 71, notify_fsgetpath: 72, notify_dup: 73, auth_settime: 74, notify_settime: 75, notify_uipc_bind: 76, auth_uipc_bind: 77, notify_uipc_connect: 78, auth_uipc_connect: 79, auth_exchangedata: 80, auth_setacl: 81, notify_setacl: 82, notify_pty_grant: 83, notify_pty_close: 84, auth_proc_check: 85, notify_proc_check: 86, auth_get_task: 87, auth_searchfs: 88, notify_searchfs: 89, auth_fcntl: 90, auth_iokit_open: 91, auth_proc_suspend_resume: 92, notify_proc_suspend_resume: 93, notify_cs_invalidated: 94, notify_get_task_name: 95, notify_trace: 96, notify_remote_thread_create: 97, auth_remount: 98, notify_remount: 99, auth_get_task_read: 100, notify_get_task_read: 101, notify_get_task_inspect: 102, notify_setuid: 103, notify_setgid: 104, notify_seteuid: 105, notify_setegid: 106, notify_setreuid: 107, notify_setregid: 108, auth_copyfile: 109, notify_copyfile: 110, notify_authentication: 111, notify_xp_malware_detected: 112, notify_xp_malware_remediated: 113, notify_lw_session_login: 114, notify_lw_session_logout: 115, notify_lw_session_lock: 116, notify_lw_session_unlock: 117, notify_screensharing_attach: 118, notify_screensharing_detach: 119, notify_openssh_login: 120, notify_openssh_logout: 121, notify_login_login: 122, notify_login_logout: 123, notify_btm_launch_item_add: 124, notify_btm_launch_item_remove: 125, notify_profile_add: 126, notify_profile_remove: 127, notify_su: 128, notify_authorization_petition: 129, notify_authorization_judgement: 130, notify_sudo: 131, notify_od_group_add: 132, notify_od_group_remove: 133, notify_od_group_set: 134, notify_od_modify_password: 135, notify_od_disable_user: 136, notify_od_enable_user: 137, notify_od_attribute_value_add: 138, notify_od_attribute_value_remove: 139, notify_od_attribute_set: 140, notify_od_create_user: 141, notify_od_create_group: 142, notify_od_delete_user: 143, notify_od_delete_group: 144, notify_xpc_connect: 145, notify_gatekeeper_user_override: 146, notify_tcc_modify: 147, reserved_0: 148, reserved_1: 149, reserved_2: 150, reserved_3: 151, reserved_4: 152, reserved_5: 153, reserved_6: 154, reserved_7: 155, reserved_8: 156 }.freeze
- VALUE_TO_SYMBOL =
SDK enum values keyed by event symbol.
SYMBOL_TO_VALUE.invert.freeze
- ALL =
All events known to the build SDK.
SYMBOL_TO_VALUE.keys.freeze
- ALL_AUTH =
All authorization events.
ALL.select { |event| event.to_s.start_with?("auth_") }.freeze
- ALL_NOTIFY =
All notification events.
ALL.select { |event| event.to_s.start_with?("notify_") }.freeze
- RESERVED =
Undocumented reserved event slots.
[:reserved_0, :reserved_1, :reserved_2, :reserved_3, :reserved_4, :reserved_5, :reserved_6, :reserved_7, :reserved_8].freeze
- CACHEABLE =
Events for which Endpoint Security accepts cached responses.
[:auth_exec, :auth_open, :auth_mmap, :auth_mount, :auth_setflags, :auth_setmode, :auth_setowner, :auth_chdir, :auth_getattrlist, :auth_chroot, :auth_utimes, :auth_getextattr, :auth_listextattr, :auth_readdir, :auth_fsgetpath, :auth_uipc_connect, :auth_proc_check, :auth_get_task, :auth_searchfs, :auth_get_task_read].freeze
Class Method Summary collapse
-
.all ⇒ Array<Symbol>
All events.
-
.all_auth ⇒ Array<Symbol>
Authorization events.
-
.all_notify ⇒ Array<Symbol>
Notification events.
-
.auth?(event) ⇒ Boolean
Whether
eventis an authorization event. -
.cacheable?(event) ⇒ Boolean
Whether
eventaccepts a cached response. -
.flags_response?(event) ⇒ Boolean
Whether
eventuses a flags response. -
.notify?(event) ⇒ Boolean
Whether
eventis a notification event. -
.reserved?(event) ⇒ Boolean
Whether
eventis an undocumented reserved slot. -
.symbol(value) ⇒ Symbol, Integer
Event symbol, or
valuewhen unknown. -
.value(event) ⇒ Integer
SDK enum value for
event.
Class Method Details
.all ⇒ Array<Symbol>
Returns all events.
500 501 |
# File 'lib/endpoint_security/generated/event_types.rb', line 500 def all = ALL # @return [Array<Symbol>] authorization events |
.all_auth ⇒ Array<Symbol>
Returns authorization events.
502 503 |
# File 'lib/endpoint_security/generated/event_types.rb', line 502 def all_auth = ALL_AUTH # @return [Array<Symbol>] notification events |
.all_notify ⇒ Array<Symbol>
Returns notification events.
504 505 |
# File 'lib/endpoint_security/generated/event_types.rb', line 504 def all_notify = ALL_NOTIFY # @return [Boolean] whether +event+ is an authorization event |
.auth?(event) ⇒ Boolean
Returns whether event is an authorization event.
506 507 |
# File 'lib/endpoint_security/generated/event_types.rb', line 506 def auth?(event) = event.to_s.start_with?("auth_") # @return [Boolean] whether +event+ is a notification event |
.cacheable?(event) ⇒ Boolean
Returns whether event accepts a cached response.
512 513 |
# File 'lib/endpoint_security/generated/event_types.rb', line 512 def cacheable?(event) = CACHEABLE.include?(event.to_sym) # @return [Boolean] whether +event+ uses a flags response |
.flags_response?(event) ⇒ Boolean
Returns whether event uses a flags response.
514 515 |
# File 'lib/endpoint_security/generated/event_types.rb', line 514 def flags_response?(event) = event.to_sym == :auth_open # @return [Integer] SDK enum value for +event+ |
.notify?(event) ⇒ Boolean
Returns whether event is a notification event.
508 509 |
# File 'lib/endpoint_security/generated/event_types.rb', line 508 def notify?(event) = event.to_s.start_with?("notify_") # @return [Boolean] whether +event+ is an undocumented reserved slot |
.reserved?(event) ⇒ Boolean
Returns whether event is an undocumented reserved slot.
510 511 |
# File 'lib/endpoint_security/generated/event_types.rb', line 510 def reserved?(event) = RESERVED.include?(event.to_sym) # @return [Boolean] whether +event+ accepts a cached response |
.symbol(value) ⇒ Symbol, Integer
Returns event symbol, or value when unknown.
518 |
# File 'lib/endpoint_security/generated/event_types.rb', line 518 def symbol(value) = VALUE_TO_SYMBOL.fetch(value, value) |
.value(event) ⇒ Integer
Returns SDK enum value for event.
516 517 |
# File 'lib/endpoint_security/generated/event_types.rb', line 516 def value(event) = SYMBOL_TO_VALUE.fetch(event.to_sym) # @return [Symbol, Integer] event symbol, or +value+ when unknown |