UserString UR55 "C52 禁止私自更改当前登录用户的权限"
UserEnforce UR55 0
UserReport UR55 0
UserProcess UR55 {Include *}
UserRule UR55 G_User {File WXCD { Include C:\\WINDOWS\\system32\\runas.exe }
}
UserString UR56 "C53 禁止私自调用文件属性修改工具"
UserEnforce UR56 0
UserReport UR56 0
UserProcess UR56 {Include *}
UserRule UR56 G_User {File WXCD { Include C:\\WINDOWS\\system32\\attrib.exe }
}
UserString UR57 "C54 禁止对Boot.ini配置文件执行编辑操作"
UserEnforce UR57 0
UserReport UR57 0
UserProcess UR57 {Include *}
UserRule UR57 G_User {File WXCD { Include C:\\WINDOWS\\system32\\bootcfg.exe }
}
UserString UR58 "C55 防止多用户同时登陆,禁用termsrv.dl"
UserEnforce UR58 0
UserReport UR58 0
UserProcess UR58 {Include *}
UserRule UR58 G_User {File WXCD { Include C:\\WINDOWS\\system32\\termsrv.dll }
}
UserString UR59 "C56 禁止使用NetMeeting功能访问远程桌面"
UserEnforce UR59 0
UserReport UR59 0
UserProcess UR59 {Include *}
UserRule UR59 G_User {File WXCD { Include C:\\WINDOWS\\system32\\mnmsrvc.exe }
}
UserString UR6 "C57 禁止在C盘根目录创建文件"
UserEnforce UR6 1
UserReport UR6 1
UserProcess UR6 {Include *}
UserRule UR6 G_User {File C { Include C:\\*.* }
}
UserString UR60 "C58 禁止“私自指定某些程序在指定的时间运行”"
UserEnforce UR60 0
UserReport UR60 0
UserProcess UR60 {Include *}
UserRule UR60 G_User {File WXCD { Include C:\\WINDOWS\\system32\\mstask.dll }
}
UserString UR61 "C59 禁止在C盘中新建任何PIF文件"
UserEnforce UR61 1
UserReport UR61 1
UserProcess UR61 {Include *}
UserRule UR61 G_User {File C { Include C:\\**\\*.pif }
}
UserString UR62 "C60 禁止私自修改本地用户帐户数据库"
UserEnforce UR62 0
UserReport UR62 0
UserProcess UR62 {Include *}
UserRule UR62 G_User {File WCD { Include C:\\WINDOWS\\system32\\config\\SAM }
}
UserString UR63 "C61 禁止在Default User目录下新建,修改,删除任何文件"
UserEnforce UR63 0
UserReport UR63 0
UserProcess UR63 {Include *}
UserRule UR63 G_User {File WCD { Include "C:\\Documents and Settings\\Default User\\**" }
}
UserString UR64 "C62 禁止在LocalService目录下新建,修改,删除任何文件"
UserEnforce UR64 0
UserReport UR64 0
UserProcess UR64 {Include *}
UserRule UR64 G_User {File C { Include "C:\\Documents and Settings\\LocalService\\**" }
}
UserString UR65 "C63 禁止在NetworkService目录下新建,修改,删除任何文件"
UserEnforce UR65 0
UserReport UR65 0
UserProcess UR65 {Include *}
UserRule UR65 G_User {File C { Include "C:\\Documents and Settings\\NetworkService\\**" }
}
UserString UR66 "C64 禁止在Application Data目录下新建任何项目"
UserEnforce UR66 0
UserReport UR66 0
UserProcess UR66 {Include *;Exclude ACDSee5.exe}
UserRule UR66 G_User {File C { Include "**\\Application Data\\*" }
}
UserString UR67 "C65 禁止修改WINDOWS目录中的任何文件"
UserEnforce UR67 0
UserReport UR67 0
UserProcess UR67 {Include *;Exclude avgas.exe Explorer.EXE FireSvc.exe FrameworkService.exe mmc.exe services.exe svchost.exe winlogon.exe WMIADAP.EXE wmiprvse.exe}
UserRule UR67 G_User {File W { Include C:\\WINDOWS\\** }
}
UserString UR68 "C66 禁止删除WINDOWS目录中的任何文件"
UserEnforce UR68 0
UserReport UR68 0
UserProcess UR68 {Include *;Exclude FrameworkService.exe mmc.exe services.exe svchost.exe WMIADAP.EXE}
UserRule UR68 G_User {File D { Include C:\\WINDOWS\\** }
}
UserString UR69 "C67 保护本机所有EXE可执行文件(防止删除)"
UserEnforce UR69 0
UserReport UR69 0
UserProcess UR69 {Include *;Exclude Explorer.EXE}
UserRule UR69 G_User {File D { Include **\\*.exe }
}
UserString UR7 "C68 禁止私自启用网络检测命令程序"
UserEnforce UR7 0
UserReport UR7 0
UserProcess UR7 {Include *}
UserRule UR7 G_User {File WXCD { Include C:\\WINDOWS\\system32\\net.exe }
}
UserString UR70 "C69 禁止在WINDOWS根目录下新建任何文件"
UserEnforce UR70 1
UserReport UR70 1
UserProcess UR70 {Include *}
UserRule UR70 G_User {File C { Include C:\\WINDOWS\\*.* }
}
UserString UR71 "C70 禁止在SYSTEM32根目录下新建任何文件"
UserEnforce UR71 1
UserReport UR71 1
UserProcess UR71 {Include *;Exclude mmc.exe svchost.exe}
UserRule UR71 G_User {File C { Include C:\\WINDOWS\\system32\\*.* }
}
UserString UR72 "C71 禁止在Downloaded Program Files目录中新建任何文件"
UserEnforce UR72 1
UserReport UR72 1
UserProcess UR72 {Include *}
UserRule UR72 G_User {File C { Include "C:\\WINDOWS\\Downloaded Program Files\\**" }
}
UserString UR73 "C72 禁止在PCHEALTH目录中新建,修改,删除任何文件"
UserEnforce UR73 0
UserReport UR73 0
UserProcess UR73 {Include *}
UserRule UR73 G_User {File WCD { Include C:\\WINDOWS\\PCHEALTH\\** }
}
UserString UR74 "C73 禁止Config目录下新建,修改,删除任何文件"
UserEnforce UR74 0
UserReport UR74 0
UserProcess UR74 {Include *}
UserRule UR74 G_User {File WCD { Include C:\\WINDOWS\\Config\\** }
}
UserString UR75 "C74 禁止在SECURITY目录下新建,修改,删除任何文件"
UserEnforce UR75 0
UserReport UR75 0
UserProcess UR75 {Include *;Exclude services.exe}
UserRule UR75 G_User {File WCD { Include C:\\WINDOWS\\security\\** }
}
UserString UR76 "C75 禁止在SYSTEM目录下新建,修改,删除任何文件"
UserEnforce UR76 0
UserReport UR76 0
UserProcess UR76 {Include *}
UserRule UR76 G_User {File WCD { Include C:\\WINDOWS\\system\\** }
}
UserString UR77 "C76 禁止在Registration目录下新建,修改,删除任何文件"
UserEnforce UR77 0
UserReport UR77 0
UserProcess UR77 {Include *}
UserRule UR77 G_User {File WCD { Include C:\\WINDOWS\\Registration\\** }
}
UserString UR78 "C77 禁止在DRIVERS目录下新建,修改,删除任何文件"
UserEnforce UR78 0
UserReport UR78 0
UserProcess UR78 {Include *;Exclude avgas.exe}
UserRule UR78 G_User {File WCD { Include C:\\WINDOWS\\system32\\drivers\\** }
}
UserString UR79 "C78 禁止启用系统还原程序"
UserEnforce UR79 0
UserReport UR79 0
UserProcess UR79 {Include *}
UserRule UR79 G_User {File WXCD { Include C:\\WINDOWS\\system32\\Restore\\** }
}
UserString UR8 "C79 禁用远程登录控制台程序"
UserEnforce UR8 1
UserReport UR8 1
UserProcess UR8 {Include *}
UserRule UR8 G_User {File WXCD { Include C:\\WINDOWS\\system32\\tlntsvr.exe }
}
UserString UR80 "C80 禁止私自调用系统配置编辑器"
UserEnforce UR80 1
UserReport UR80 1
UserProcess UR80 {Include *}
UserRule UR80 G_User {File WXCD { Include C:\\WINDOWS\\system32\\sysedit.exe }
}
UserString UR81 "C81 保护系统盘中的BOOT.INI配置文件"
UserEnforce UR81 1
UserReport UR81 1
UserProcess UR81 {Include *}
UserRule UR81 G_User {File WCD { Include C:\\boot.ini }
}
UserString UR82 "C82 禁止在C盘中新建CMD文件(防范某些蠕虫)"
UserEnforce UR82 1
UserReport UR82 1
UserProcess UR82 {Include *}
UserRule UR82 G_User {File C { Include C:\\**\\*.cmd }
}
UserString UR83 "C83 禁止在C盘中新建HTT文件(防范某些病毒)"
UserEnforce UR83 0
UserReport UR83 0
UserProcess UR83 {Include *}
UserRule UR83 G_User {File C { Include C:\\**\\*.htt }
}
UserString UR84 "C84 保护WINDOWS的\"系统文件替换\"备份目录"
UserEnforce UR84 1
UserReport UR84 1
UserProcess UR84 {Include *}
UserRule UR84 G_User {File WCD { Include C:\\WINDOWS\\LastGood\\** }
}
UserString UR85 "C85 保护WINDOWS的\"最后一次正确启动配置\"备份文件目录"
UserEnforce UR85 1
UserReport UR85 1
UserProcess UR85 {Include *}
UserRule UR85 G_User {File WCD { Include C:\\WINDOWS\\LastGood.Tmp\\** }
}
UserString UR86 "C86 保护系统中的WININIT.INI配置文件"
UserEnforce UR86 1
UserReport UR86 1
UserProcess UR86 {Include *}
UserRule UR86 G_User {File WCD { Include C:\\WINDOWS\\wininit.ini }
}
UserString UR87 "C87 禁止在C盘中新建,修改任何CPL文件(防范某些木马)"
UserEnforce UR87 1
UserReport UR87 1
UserProcess UR87 {Include *}
UserRule UR87 G_User {File WC { Include C:\\**\\*.cpl }
} |