Host Intrusion Detection System Administrator's Guide Release 3.1

Templates and Alerts
Alert Summary
Appendix A
126
Setuid file created A privileged setuid file
was created,
potentially created, or
the setuid bit was
turned on a regular
file owned by a
privileged user, or the
owner of a setuid file
was changed from a
non privileged user to
a privileged user.
1 Creation and
Modification of Setuid
File Template
Setuid file modified A privileged setuid file
was truncated or
potentially modified.
1 Creation and
Modification of Setuid
file template
Append-only file
modified or
potentially modified
An append-only file
was truncated,
potentially truncated,
deleted, renamed, or
opened with write
permission in
non-append mode.
2 Changes to Log File
Template
World-writable file
created
A file with
world-writable
permission was
created by a privileged
user, the
world-writable bit was
set on an existing file
owned by a privileged
user, the owner of a
world-writable file was
changed to a
privileged user from a
non privileged user, or
a world-writable file
owned by a privileged
user was renamed
from a location that is
not being monitored to
a location that is being
monitored.
3 Creation of
World-Writable File
Template
Non-owned file being
modified
A file was truncated,
deleted, or renamed by
a user other than the
owner of the file.
2 Modification of
Another User’s File
Template
Table A-1 Detection Templates (Continued)
Alert Attack Alert Severity Detection Template