Reference Guide

Security Management Server v10.2.10 AdminHelp
103
Memory Protection
Selecting this option logs any Memory Exploit Attempts that might be considered an attack from any of
the Tenant’s devices to the Syslog server.
There are four types of Memory Exploit actions:
None: Allowed because no policy has been defined for this violation.
Allowed: Allowed by policy.
Blocked: Blocked from running by policy.
Terminated: Process has been terminated.
Example Message of Memory Protection Event:
Script Control
Selecting this option logs any newly found scripts that have been blocked or have triggered an alert to
the Syslog server.
Syslog Script Control events contain the following properties:
Alert: The script is allowed to run. A script control event is sent to the Dell Server.
Block: The script is not allowed to run. A script control event is sent to the Dell Server.
Example Message of Script Control
Threats
Select this option to log any newly found threats or changes observed for any existing threat, to the
Syslog server. Changes include a threat being Removed, Quarantined, Waived, or Executed.
There are five types of Threat Events:
threat_found: A new threat has been found in an Unsafe status.
threat_removed: An existing threat has been Removed.
threat_quarantined: A new threat has been found in the Quarantine status.
threat_waived: A new threat has been found in the Waived status.