-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathfilescreen.xml
More file actions
18 lines (18 loc) · 3.05 KB
/
Copy pathfilescreen.xml
File metadata and controls
18 lines (18 loc) · 3.05 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
<?xml version="1.0" ?>
<Root >
<Header DatabaseVersion = '2.0' ></Header>
<QuotaTemplates ></QuotaTemplates>
<DatascreenTemplates >
<DatascreenTemplate Name = 'Detect-Crypto' Id = '{D4026A81-E75A-5923-81E2-D21085CDC920}' Flags = '0' Description = '' >
<BlockedGroups >
<FileGroup FileGroupId = '{6AFBC4BF-AED6-2501-BB6E-DBB2C10B3C50}' Name = 'Detect-Crypto' ></FileGroup>
</BlockedGroups>
<FileGroupActions >
<Action Type="1" Id="{8B1D2A05-48A2-5EA4-1830-A4B902E37F01}" EventType="2" MessageText="User%s[Source%sIo%sOwner]%sattempted%sto%ssave%s[Source%sFile%sPath]%sto%s[File%sScreen%sPath]%son%sthe%s[Server]%sserver.%sThis%sfile%sis%sin%sthe%s[Violated%sFile%sGroup]%sfile%sgroup,%swhich%sis%snot%spermitted%son%sthe%sserver." />
<Action Type="3" Id="{B25A0ACE-E428-5A0B-C206-D5D22669165A}" ExecutablePath="C:\Detect-Crypto\Detect-Crypto.bat" Arguments="" WorkingDirectory="C:\" Account="3" MonitorCommand="0" KillTimeOut="0" LogResult="1" />
<Action Type="2" Id="{D2B1E03A-BAD3-420F-921F-2A7B7850F229}" MailFrom="" MailReplyTo="" MailTo="[Source%sIo%sOwner%sEmail]" MailCc="" MailBcc="" MailSubject="URGENT%s-%sRansomware%svirus%sDETECTED%son%s[Server]" MessageText="User%s[Source%sIo%sOwner]%sattempted%sto%ssave%s[Source%sFile%sPath]%sto%s[File%sScreen%sPath]%son%sthe%s[Server]%sserver.%sThis%sfile%sis%sin%sthe%s[Violated%sFile%sGroup]%sfile%sgroup,%swhich%sis%snot%spermitted%son%sthe%sserver." />
</FileGroupActions>
</DatascreenTemplate>
</DatascreenTemplates>
<FileGroups ></FileGroups>
</Root>