public class AbnormalProcessSystemChildRuleInfo extends AbstractModel
header, skipSign| Constructor and Description | 
|---|
| AbnormalProcessSystemChildRuleInfo() | 
| AbnormalProcessSystemChildRuleInfo(AbnormalProcessSystemChildRuleInfo source)NOTE: Any ambiguous key set via .set("AnyKey", "value") will be a shallow copy,
       and any explicit key, i.e Foo, set via .setFoo("value") will be a deep copy. | 
| Modifier and Type | Method and Description | 
|---|---|
| Boolean | getIsEnable()Get 子策略状态,true为开启,false为关闭 | 
| String | getRuleId()Get 子策略Id | 
| String | getRuleLevel()Get 威胁等级,HIGH:高,MIDDLE:中,LOW:低 | 
| String | getRuleMode()Get 策略模式,  RULE_MODE_RELEASE: 放行
   RULE_MODE_ALERT: 告警
   RULE_MODE_HOLDUP:拦截 | 
| String | getRuleType()Get 子策略检测的行为类型
PROXY_TOOL: 代理软件
TRANSFER_CONTROL:横向渗透
ATTACK_CMD: 恶意命令
REVERSE_SHELL:反弹shell
FILELESS:无文件程序执行
RISK_CMD:高危命令
ABNORMAL_CHILD_PROC: 敏感服务异常子进程启动 | 
| void | setIsEnable(Boolean IsEnable)Set 子策略状态,true为开启,false为关闭 | 
| void | setRuleId(String RuleId)Set 子策略Id | 
| void | setRuleLevel(String RuleLevel)Set 威胁等级,HIGH:高,MIDDLE:中,LOW:低 | 
| void | setRuleMode(String RuleMode)Set 策略模式,  RULE_MODE_RELEASE: 放行
   RULE_MODE_ALERT: 告警
   RULE_MODE_HOLDUP:拦截 | 
| void | setRuleType(String RuleType)Set 子策略检测的行为类型
PROXY_TOOL: 代理软件
TRANSFER_CONTROL:横向渗透
ATTACK_CMD: 恶意命令
REVERSE_SHELL:反弹shell
FILELESS:无文件程序执行
RISK_CMD:高危命令
ABNORMAL_CHILD_PROC: 敏感服务异常子进程启动 | 
| void | toMap(HashMap<String,String> map,
     String prefix)Internal implementation, normal users should not use it. | 
any, fromJsonString, getBinaryParams, GetHeader, getMultipartRequestParams, getSkipSign, isStream, set, SetHeader, setParamArrayObj, setParamArraySimple, setParamObj, setParamSimple, setSkipSign, toJsonStringpublic AbnormalProcessSystemChildRuleInfo()
public AbnormalProcessSystemChildRuleInfo(AbnormalProcessSystemChildRuleInfo source)
public String getRuleId()
public void setRuleId(String RuleId)
RuleId - 子策略Idpublic Boolean getIsEnable()
public void setIsEnable(Boolean IsEnable)
IsEnable - 子策略状态,true为开启,false为关闭public String getRuleMode()
public void setRuleMode(String RuleMode)
RuleMode - 策略模式,  RULE_MODE_RELEASE: 放行
   RULE_MODE_ALERT: 告警
   RULE_MODE_HOLDUP:拦截public String getRuleType()
public void setRuleType(String RuleType)
RuleType - 子策略检测的行为类型
PROXY_TOOL: 代理软件
TRANSFER_CONTROL:横向渗透
ATTACK_CMD: 恶意命令
REVERSE_SHELL:反弹shell
FILELESS:无文件程序执行
RISK_CMD:高危命令
ABNORMAL_CHILD_PROC: 敏感服务异常子进程启动public String getRuleLevel()
public void setRuleLevel(String RuleLevel)
RuleLevel - 威胁等级,HIGH:高,MIDDLE:中,LOW:低Copyright © 2025. All rights reserved.