Class: Google::Apis::SecuritycenterV1beta2::KernelRootkit

Inherits:
Object
  • Object
show all
Includes:
Core::Hashable, Core::JsonObjectSupport
Defined in:
lib/google/apis/securitycenter_v1beta2/classes.rb,
lib/google/apis/securitycenter_v1beta2/representations.rb,
lib/google/apis/securitycenter_v1beta2/representations.rb

Overview

Kernel mode rootkit signatures.

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(**args) ⇒ KernelRootkit

Returns a new instance of KernelRootkit.



5951
5952
5953
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5951

def initialize(**args)
   update!(**args)
end

Instance Attribute Details

#name ⇒ String

Rootkit name, when available. Corresponds to the JSON property name

Returns:

  • (String)


5895
5896
5897
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5895

def name
  @name
end

#unexpected_code_modification ⇒ Boolean Also known as: unexpected_code_modification?

True if unexpected modifications of kernel code memory are present. Corresponds to the JSON property unexpectedCodeModification

Returns:

  • (Boolean)


5900
5901
5902
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5900

def unexpected_code_modification
  @unexpected_code_modification
end

#unexpected_ftrace_handler ⇒ Boolean Also known as: unexpected_ftrace_handler?

True if ftrace points are present with callbacks pointing to regions that are not in the expected kernel or module code range. Corresponds to the JSON property unexpectedFtraceHandler

Returns:

  • (Boolean)


5907
5908
5909
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5907

def unexpected_ftrace_handler
  @unexpected_ftrace_handler
end

#unexpected_interrupt_handler ⇒ Boolean Also known as: unexpected_interrupt_handler?

True if interrupt handlers that are are not in the expected kernel or module code regions are present. Corresponds to the JSON property unexpectedInterruptHandler

Returns:

  • (Boolean)


5914
5915
5916
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5914

def unexpected_interrupt_handler
  @unexpected_interrupt_handler
end

#unexpected_kernel_code_pages ⇒ Boolean Also known as: unexpected_kernel_code_pages?

True if kernel code pages that are not in the expected kernel or module code regions are present. Corresponds to the JSON property unexpectedKernelCodePages

Returns:

  • (Boolean)


5921
5922
5923
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5921

def unexpected_kernel_code_pages
  @unexpected_kernel_code_pages
end

#unexpected_kprobe_handler ⇒ Boolean Also known as: unexpected_kprobe_handler?

True if kprobe points are present with callbacks pointing to regions that are not in the expected kernel or module code range. Corresponds to the JSON property unexpectedKprobeHandler

Returns:

  • (Boolean)


5928
5929
5930
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5928

def unexpected_kprobe_handler
  @unexpected_kprobe_handler
end

#unexpected_processes_in_runqueue ⇒ Boolean Also known as: unexpected_processes_in_runqueue?

True if unexpected processes in the scheduler run queue are present. Such processes are in the run queue, but not in the process task list. Corresponds to the JSON property unexpectedProcessesInRunqueue

Returns:

  • (Boolean)


5935
5936
5937
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5935

def unexpected_processes_in_runqueue
  @unexpected_processes_in_runqueue
end

#unexpected_read_only_data_modification ⇒ Boolean Also known as: unexpected_read_only_data_modification?

True if unexpected modifications of kernel read-only data memory are present. Corresponds to the JSON property unexpectedReadOnlyDataModification

Returns:

  • (Boolean)


5941
5942
5943
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5941

def unexpected_read_only_data_modification
  @unexpected_read_only_data_modification
end

#unexpected_system_call_handler ⇒ Boolean Also known as: unexpected_system_call_handler?

True if system call handlers that are are not in the expected kernel or module code regions are present. Corresponds to the JSON property unexpectedSystemCallHandler

Returns:

  • (Boolean)


5948
5949
5950
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5948

def unexpected_system_call_handler
  @unexpected_system_call_handler
end

Instance Method Details

#update!(**args) ⇒ Object

Update properties of this object



5956
5957
5958
5959
5960
5961
5962
5963
5964
5965
5966
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 5956

def update!(**args)
  @name = args[:name] if args.key?(:name)
  @unexpected_code_modification = args[:unexpected_code_modification] if args.key?(:unexpected_code_modification)
  @unexpected_ftrace_handler = args[:unexpected_ftrace_handler] if args.key?(:unexpected_ftrace_handler)
  @unexpected_interrupt_handler = args[:unexpected_interrupt_handler] if args.key?(:unexpected_interrupt_handler)
  @unexpected_kernel_code_pages = args[:unexpected_kernel_code_pages] if args.key?(:unexpected_kernel_code_pages)
  @unexpected_kprobe_handler = args[:unexpected_kprobe_handler] if args.key?(:unexpected_kprobe_handler)
  @unexpected_processes_in_runqueue = args[:unexpected_processes_in_runqueue] if args.key?(:unexpected_processes_in_runqueue)
  @unexpected_read_only_data_modification = args[:unexpected_read_only_data_modification] if args.key?(:unexpected_read_only_data_modification)
  @unexpected_system_call_handler = args[:unexpected_system_call_handler] if args.key?(:unexpected_system_call_handler)
end