fscanary command - github.com/fukawi2/fscanary - Go Packages

fscanary

command module
v0.4.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Apr 7, 2018 License: MIT Imports: 13 Imported by: 0

README

fscanary

Monitor and report or action file systems for specific files.

Description

fscanary aims to be a replacement for some features of Microsoft's File Server Resource Manager (FSRM), particularly in detecting creation of specific files and notifying the system admin of those files.

For example, it is likely to be desirable to have an alert when a user saves and executable file to the company file server.

Getting Started

Deploy fscanary to your preferred bin location (eg, /usr/local/bin/fscanary)

Configuration

The default location of the config file is OS-specific and is shown in the output of fscnary -help. It can be overridden with the -config command line argument -config. For example:

fscanary -config /root/fscanary.conf

The configuration file is INI-style and has a global section for general configuration, then one or more sections to set up watches.

Example configuration file:

email = admin@example.com
smtp_server = smarthost
smtp_from = fscanary@example.com

[executables]
path = /home
pattern = *.exe
pattern = *.bat
pattern = *.js
pattern = *.bin
pattern = *.cmd
pattern = *.cpl
pattern = *.dll
pattern = *.lnk
pattern = *.ps1
pattern = *.scr
notify = yes
quarantine = yes
dest = /quarantined

Contributing

Pull requests welcomed! Please keep the following points in mind:

  • One feature change/bug fix per pull request.
    • Multiple minor changes such as spelling may be in a single PR.
  • Documentation must be updated with the PR where the change warrants documentation changes.

Authors

License

This project is licensed under the MIT License - see the LICENSE.md file for details

Acknowledgments

Documentation

The Go Gopher

There is no documentation for this package.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL