Adaptive Application Controls - List
Obtiene una lista de grupos de máquinas de control de aplicaciones para la suscripción.
GET https://management.azure.com/subscriptions/{subscriptionId}/providers/Microsoft.Security/applicationWhitelistings?api-version=2020-01-01
GET https://management.azure.com/subscriptions/{subscriptionId}/providers/Microsoft.Security/applicationWhitelistings?api-version=2020-01-01&includePathRecommendations={includePathRecommendations}&summary={summary}
Parámetros de identificador URI
Nombre | En | Requerido | Tipo | Description |
---|---|---|---|---|
subscription
|
path | True |
string |
Identificador de suscripción de Azure Regex pattern: |
api-version
|
query | True |
string |
Versión de API para la operación |
include
|
query |
boolean |
Incluir las reglas de directiva |
|
summary
|
query |
boolean |
Devolver la salida en un formulario resumido |
Respuestas
Nombre | Tipo | Description |
---|---|---|
200 OK |
Aceptar |
|
Other Status Codes |
Respuesta de error que describe el motivo del error de la operación. |
Seguridad
azure_auth
Flujo OAuth2 de Azure Active Directory
Type:
oauth2
Flow:
implicit
Authorization URL:
https://login.microsoftonline.com/common/oauth2/authorize
Scopes
Nombre | Description |
---|---|
user_impersonation | suplantación de su cuenta de usuario |
Ejemplos
Gets a list of application control groups of machines for the subscription
Sample Request
GET https://management.azure.com/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/applicationWhitelistings?api-version=2020-01-01&includePathRecommendations=True&summary=False
Sample Response
{
"value": [
{
"id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/locations/centralus/applicationWhitelistings/AMIT-VA",
"name": "AMIT-VA",
"type": "Microsoft.Security/applicationWhitelistings",
"location": "centralus",
"properties": {
"recommendationStatus": "Recommended",
"enforcementMode": "Audit",
"protectionMode": {
"exe": "Audit",
"msi": "Audit",
"script": "None"
},
"vmRecommendations": [
{
"configurationStatus": "Configured",
"resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/erelh-dsc/providers/microsoft.compute/virtualmachines/erelh-14011",
"recommendationAction": "Recommended",
"enforcementSupport": "Supported"
},
{
"configurationStatus": "Configured",
"resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/amit-va/providers/microsoft.compute/virtualmachines/ream-test",
"recommendationAction": "Recommended",
"enforcementSupport": "Supported"
},
{
"configurationStatus": "Configured",
"resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/v-arrikl-scheduledapps/providers/microsoft.compute/virtualmachines/v-arrikl-14060",
"recommendationAction": "Recommended",
"enforcementSupport": "Supported"
}
],
"pathRecommendations": [
{
"path": "C:\\Windows\\SoftwareDistribution\\Download\\Install\\Windows-KB890830-x64-V5.53-delta.exe",
"type": "File",
"common": true,
"action": "Remove",
"usernames": [
{
"username": "LOCAL SYSTEM",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-5-18"
],
"fileType": "Exe",
"configurationStatus": "NoStatus"
},
{
"path": "C:\\WindowsAzure\\GuestAgent_2.7.1198.822\\CollectGuestLogs.exe",
"type": "File",
"common": true,
"action": "Remove",
"usernames": [
{
"username": "LOCAL SYSTEM",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-5-18"
],
"fileType": "Exe",
"configurationStatus": "NoStatus"
},
{
"path": "C:\\Windows\\System32\\wbem\\WmiPrvSE.exe",
"type": "PublisherSignature",
"publisherInfo": {
"publisherName": "O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US",
"productName": "*",
"binaryName": "*",
"version": "0.0.0.0"
},
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "Everyone",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-5-18",
"S-1-1-0"
],
"fileType": "Exe",
"configurationStatus": "Configured"
},
{
"path": "%OSDRIVE%\\WINDOWSAZURE\\SECAGENT\\WASECAGENTPROV.EXE",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "Everyone",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Exe",
"configurationStatus": "Configured"
}
],
"configurationStatus": "Configured",
"issues": [],
"sourceSystem": "Azure_AppLocker"
}
},
{
"id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/locations/centralus/applicationWhitelistings/ERELGROUP1",
"name": "ERELGROUP1",
"type": "Microsoft.Security/applicationWhitelistings",
"location": "centralus",
"properties": {
"recommendationStatus": "Recommended",
"enforcementMode": "Audit",
"protectionMode": {
"exe": "Audit",
"msi": "None",
"script": "None"
},
"vmRecommendations": [
{
"configurationStatus": "Configured",
"resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/erelh-stable/providers/microsoft.compute/virtualmachines/erelh-16090",
"recommendationAction": "Recommended",
"enforcementSupport": "NotSupported"
}
],
"pathRecommendations": [
{
"path": "[Exe] O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\\*\\*\\0.0.0.0",
"type": "PublisherSignature",
"publisherInfo": {
"publisherName": "O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US",
"productName": "*",
"binaryName": "*",
"version": "0.0.0.0"
},
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "Everyone",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Exe",
"configurationStatus": "Configured"
}
],
"configurationStatus": "Configured",
"issues": [],
"sourceSystem": "Azure_AppLocker"
}
},
{
"id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/locations/centralus/applicationWhitelistings/GROUP1",
"name": "GROUP1",
"type": "Microsoft.Security/applicationWhitelistings",
"location": "centralus",
"properties": {
"recommendationStatus": "Recommended",
"enforcementMode": "Audit",
"protectionMode": {
"exe": "Audit",
"msi": "None",
"script": "None"
},
"vmRecommendations": [
{
"configurationStatus": "Configured",
"resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/talk-va/providers/microsoft.compute/virtualmachines/tal-win-vm",
"recommendationAction": "Recommended",
"enforcementSupport": "Supported"
},
{
"configurationStatus": "Configured",
"resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/talk-va/providers/microsoft.compute/virtualmachines/tal-win-vm-jit",
"recommendationAction": "Recommended",
"enforcementSupport": "Supported"
},
{
"configurationStatus": "Configured",
"resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/myresourcegroup/providers/microsoft.compute/virtualmachines/myvmweb",
"recommendationAction": "Recommended",
"enforcementSupport": "Supported"
},
{
"configurationStatus": "Configured",
"resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/v-arrikl-scheduledapps/providers/microsoft.compute/virtualmachines/v-arrikl-14061",
"recommendationAction": "Recommended",
"enforcementSupport": "Supported"
}
],
"pathRecommendations": [
{
"path": "[Exe] O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\\*\\*\\0.0.0.0",
"type": "PublisherSignature",
"publisherInfo": {
"publisherName": "O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US",
"productName": "*",
"binaryName": "*",
"version": "0.0.0.0"
},
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "Everyone",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Exe",
"configurationStatus": "Configured"
},
{
"path": "%OSDRIVE%\\WINDOWSAZURE\\SECAGENT\\WASECAGENTPROV.EXE",
"type": "ProductSignature",
"publisherInfo": {
"publisherName": "CN=MICROSOFT AZURE DEPENDENCY CODE SIGN",
"productName": "MICROSOFT® COREXT",
"binaryName": "*",
"version": "0.0.0.0"
},
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "NT AUTHORITY\\SYSTEM",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Exe",
"configurationStatus": "Configured"
},
{
"path": "%PROGRAMFILES%\\RAPID7\\INSIGHT AGENT\\COMPONENTS\\INSIGHT_AGENT\\2.6.7.9\\GET_PROXY.EXE",
"type": "PublisherSignature",
"publisherInfo": {
"publisherName": "O=RAPID7 LLC, L=BOSTON, S=MASSACHUSETTS, C=US",
"productName": "*",
"binaryName": "*",
"version": "0.0.0.0"
},
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "NT AUTHORITY\\SYSTEM",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Exe",
"configurationStatus": "Configured"
},
{
"path": "%PROGRAMFILES%\\GOOGLE\\CHROME\\APPLICATION\\CHROME.EXE",
"type": "ProductSignature",
"publisherInfo": {
"publisherName": "O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US",
"productName": "GOOGLE CHROME",
"binaryName": "*",
"version": "0.0.0.0"
},
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "NT AUTHORITY\\SYSTEM",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Exe",
"configurationStatus": "Configured"
},
{
"path": "O=GOOGLE INC, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US\\GOOGLE UPDATE\\*\\0.0.0.0",
"type": "ProductSignature",
"publisherInfo": {
"publisherName": "O=GOOGLE INC, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US",
"productName": "GOOGLE UPDATE",
"binaryName": "*",
"version": "0.0.0.0"
},
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "NT AUTHORITY\\SYSTEM",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Exe",
"configurationStatus": "Configured"
}
],
"configurationStatus": "Configured",
"issues": [],
"sourceSystem": "Azure_AppLocker"
}
},
{
"id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/locations/westeurope/applicationWhitelistings/GROUP1",
"name": "GROUP1",
"type": "Microsoft.Security/applicationWhitelistings",
"location": "westeurope",
"properties": {
"recommendationStatus": "Recommended",
"enforcementMode": "Audit",
"protectionMode": {
"executable": "Audit"
},
"vmRecommendations": [
{
"configurationStatus": "Configured",
"resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/nic-no-pip/providers/microsoft.compute/virtualmachines/nic-no-pip-vm",
"recommendationAction": "Recommended",
"enforcementSupport": "Unknown"
}
],
"pathRecommendations": [
{
"path": "/sbin/init",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/sbin/upstart-udev-bridge",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/lib/systemd/systemd-udevd",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/sbin/upstart-socket-bridge",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/sbin/dhclient",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/bin/python3.4",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/sbin/upstart-file-bridge",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/bin/dbus-daemon",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "messagebus",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/lib/systemd/systemd-logind",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/sbin/getty",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/sbin/atd",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/sbin/cron",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/sbin/acpid",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/sbin/sshd",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/lib/linux-lts-xenial-tools-4.4.0-103/hv_vss_daemon",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/lib/linux-lts-xenial-tools-4.4.0-103/hv_kvp_daemon",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/sbin/nscd",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "unscd",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/sbin/ntpd",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "ntp",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/opt/microsoft/auoms/bin/auomscollect",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/opt/omi/bin/omiserver",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/opt/omi/bin/omiengine",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "omi",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/opt/omi/bin/omiagent",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/sbin/rsyslogd",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "syslog",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/bin/python2.7",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
},
{
"username": "omsagent",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/opt/microsoft/omsagent/ruby/bin/ruby",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "omsagent",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/opt/microsoft/auoms/bin/auoms",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/local/qualys/cloud-agent/bin/qualys-cloud-agent",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/bin/dash",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "omsagent",
"recommendationAction": "Recommended"
},
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/bin/sleep",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "omsagent",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/opt/dsc/bin/dsc_host",
"type": "File",
"common": false,
"action": "Recommended",
"usernames": [
{
"username": "omsagent",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/bin/sudo",
"type": "File",
"common": false,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/bin/bash",
"type": "File",
"common": false,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/bin/apt-get",
"type": "File",
"common": false,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/lib/apt/methods/http",
"type": "File",
"common": false,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/lib/apt/methods/gpgv",
"type": "File",
"common": false,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/lib/apt/methods/copy",
"type": "File",
"common": false,
"action": "Recommended",
"usernames": [
{
"username": "root",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/usr/bin/pgrep",
"type": "File",
"common": true,
"action": "Recommended",
"usernames": [
{
"username": "omsagent",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
},
{
"path": "/opt/microsoft/omsconfig/bin/omsconsistencyinvoker",
"type": "File",
"common": false,
"action": "Recommended",
"usernames": [
{
"username": "omsagent",
"recommendationAction": "Recommended"
}
],
"userSids": [
"S-1-1-0"
],
"fileType": "Executable",
"configurationStatus": "Configured"
}
],
"configurationStatus": "Configured",
"issues": [
{
"issue": "ExecutableViolationsAudited",
"numberOfVms": 1
}
],
"sourceSystem": "Azure_AuditD"
}
}
]
}
Definiciones
Nombre | Description |
---|---|
Adaptive |
|
Adaptive |
Representa una lista de grupos de máquinas virtuales o servidores y un conjunto de reglas recomendados por Microsoft Defender para que se permita la nube. |
Adaptive |
Una alerta que las máquinas de un grupo pueden tener |
Adaptive |
Representa un resumen de las alertas del grupo de máquinas. |
Cloud |
Respuesta de error común para todas las API de Azure Resource Manager para devolver los detalles de error de las operaciones con errores. (Esto también sigue el formato de respuesta de error de OData). |
Cloud |
Detalle del error. |
Configuration |
Estado de configuración del grupo o regla de máquinas |
Enforcement |
El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas |
Enforcement |
La compatibilidad de la máquina con la característica Aplicar |
Error |
Información adicional sobre el error de administración de recursos. |
File |
Tipo del archivo (para archivos linux: se usa ejecutable) |
Path |
Representa una ruta de acceso que se recomienda permitir y sus propiedades. |
Protection |
Modo de protección de los tipos de colección o archivo. Exe/Msi/Script se usan para Windows, el ejecutable se usa para Linux. |
Publisher |
Representa la información del publicador de un proceso o regla. |
Recommendation |
Acción de recomendación de la máquina o regla |
Recommendation |
El estado de recomendación inicial del grupo de máquinas o la máquina |
Recommendation |
Tipo de la regla que se va a permitir |
Source |
El tipo de origen del grupo de máquinas |
User |
Representa un usuario que se recomienda permitir para una regla determinada. |
Vm |
Representa una máquina que forma parte de un grupo de máquinas. |
AdaptiveApplicationControlGroup
Nombre | Tipo | Description |
---|---|---|
id |
string |
Id. de recurso |
location |
string |
Ubicación donde se almacena el recurso |
name |
string |
Nombre del recurso |
properties.configurationStatus |
Estado de configuración del grupo o regla de máquinas |
|
properties.enforcementMode |
El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas |
|
properties.issues |
Representa un resumen de las alertas del grupo de máquinas. |
|
properties.pathRecommendations |
Representa una ruta de acceso que se recomienda permitir y sus propiedades. |
|
properties.protectionMode |
Modo de protección de los tipos de colección o archivo. Exe/Msi/Script se usan para Windows, el ejecutable se usa para Linux. |
|
properties.recommendationStatus |
El estado de recomendación inicial del grupo de máquinas o la máquina |
|
properties.sourceSystem |
El tipo de origen del grupo de máquinas |
|
properties.vmRecommendations |
Representa una máquina que forma parte de un grupo de máquinas. |
|
type |
string |
Tipo de recurso |
AdaptiveApplicationControlGroups
Representa una lista de grupos de máquinas virtuales o servidores y un conjunto de reglas recomendados por Microsoft Defender para que se permita la nube.
Nombre | Tipo | Description |
---|---|---|
value |
AdaptiveApplicationControlIssue
Una alerta que las máquinas de un grupo pueden tener
Nombre | Tipo | Description |
---|---|---|
ExecutableViolationsAudited |
string |
|
MsiAndScriptViolationsAudited |
string |
|
MsiAndScriptViolationsBlocked |
string |
|
RulesViolatedManually |
string |
|
ViolationsAudited |
string |
|
ViolationsBlocked |
string |
AdaptiveApplicationControlIssueSummary
Representa un resumen de las alertas del grupo de máquinas.
Nombre | Tipo | Description |
---|---|---|
issue |
Una alerta que las máquinas de un grupo pueden tener |
|
numberOfVms |
number |
Número de máquinas del grupo que tienen esta alerta |
CloudError
Respuesta de error común para todas las API de Azure Resource Manager para devolver los detalles de error de las operaciones con errores. (Esto también sigue el formato de respuesta de error de OData).
Nombre | Tipo | Description |
---|---|---|
error.additionalInfo |
Información adicional del error. |
|
error.code |
string |
Código de error. |
error.details |
Los detalles del error. |
|
error.message |
string |
El mensaje de error. |
error.target |
string |
Destino del error. |
CloudErrorBody
Detalle del error.
Nombre | Tipo | Description |
---|---|---|
additionalInfo |
Información adicional del error. |
|
code |
string |
Código de error. |
details |
Los detalles del error. |
|
message |
string |
El mensaje de error. |
target |
string |
Destino del error. |
ConfigurationStatus
Estado de configuración del grupo o regla de máquinas
Nombre | Tipo | Description |
---|---|---|
Configured |
string |
|
Failed |
string |
|
InProgress |
string |
|
NoStatus |
string |
|
NotConfigured |
string |
EnforcementMode
El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas
Nombre | Tipo | Description |
---|---|---|
Audit |
string |
|
Enforce |
string |
|
None |
string |
EnforcementSupport
La compatibilidad de la máquina con la característica Aplicar
Nombre | Tipo | Description |
---|---|---|
NotSupported |
string |
|
Supported |
string |
|
Unknown |
string |
ErrorAdditionalInfo
Información adicional sobre el error de administración de recursos.
Nombre | Tipo | Description |
---|---|---|
info |
object |
Información adicional. |
type |
string |
Tipo de información adicional. |
FileType
Tipo del archivo (para archivos linux: se usa ejecutable)
Nombre | Tipo | Description |
---|---|---|
Dll |
string |
|
Exe |
string |
|
Executable |
string |
|
Msi |
string |
|
Script |
string |
|
Unknown |
string |
PathRecommendation
Representa una ruta de acceso que se recomienda permitir y sus propiedades.
Nombre | Tipo | Description |
---|---|---|
action |
Acción de recomendación de la máquina o regla |
|
common |
boolean |
Si la aplicación se ejecuta normalmente en el equipo |
configurationStatus |
Estado de configuración del grupo o regla de máquinas |
|
fileType |
Tipo del archivo (para archivos linux: se usa ejecutable) |
|
path |
string |
Ruta de acceso completa del archivo o un identificador de la aplicación |
publisherInfo |
Representa la información del publicador de un proceso o regla. |
|
type |
Tipo de la regla que se va a permitir |
|
userSids |
string[] |
Un identificador de seguridad |
usernames |
Representa un usuario que se recomienda permitir para una regla determinada. |
ProtectionMode
Modo de protección de los tipos de colección o archivo. Exe/Msi/Script se usan para Windows, el ejecutable se usa para Linux.
Nombre | Tipo | Description |
---|---|---|
exe |
El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas |
|
executable |
El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas |
|
msi |
El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas |
|
script |
El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas |
PublisherInfo
Representa la información del publicador de un proceso o regla.
Nombre | Tipo | Description |
---|---|---|
binaryName |
string |
Campo "OriginalName" tomado del recurso de versión del archivo |
productName |
string |
Nombre del producto tomado del recurso de versión del archivo |
publisherName |
string |
Campo Asunto del certificado x.509 usado para firmar el código, con los siguientes campos: O = Organización, L = Localidad, S = Estado o Provincia y C = País |
version |
string |
La versión del archivo binario tomada del recurso de versión del archivo |
RecommendationAction
Acción de recomendación de la máquina o regla
Nombre | Tipo | Description |
---|---|---|
Add |
string |
|
Recommended |
string |
|
Remove |
string |
RecommendationStatus
El estado de recomendación inicial del grupo de máquinas o la máquina
Nombre | Tipo | Description |
---|---|---|
NoStatus |
string |
|
NotAvailable |
string |
|
NotRecommended |
string |
|
Recommended |
string |
RecommendationType
Tipo de la regla que se va a permitir
Nombre | Tipo | Description |
---|---|---|
BinarySignature |
string |
|
File |
string |
|
FileHash |
string |
|
ProductSignature |
string |
|
PublisherSignature |
string |
|
VersionAndAboveSignature |
string |
SourceSystem
El tipo de origen del grupo de máquinas
Nombre | Tipo | Description |
---|---|---|
Azure_AppLocker |
string |
|
Azure_AuditD |
string |
|
NonAzure_AppLocker |
string |
|
NonAzure_AuditD |
string |
|
None |
string |
UserRecommendation
Representa un usuario que se recomienda permitir para una regla determinada.
Nombre | Tipo | Description |
---|---|---|
recommendationAction |
Acción de recomendación de la máquina o regla |
|
username |
string |
Representa un usuario que se recomienda permitir para una regla determinada. |
VmRecommendation
Representa una máquina que forma parte de un grupo de máquinas.
Nombre | Tipo | Description |
---|---|---|
configurationStatus |
Estado de configuración del grupo o regla de máquinas |
|
enforcementSupport |
La compatibilidad de la máquina con la característica Aplicar |
|
recommendationAction |
Acción de recomendación de la máquina o regla |
|
resourceId |
string |
El identificador de recurso completo de la máquina |