Skip to main content

experimentersoftroll422-security-loader

Windows filesystem security monitoring, access control, and encryption workflow integration using EaseFilter SDK with Rust bindings

الانتقال إلى التثبيت

معلومات المصدر

المستودع
reason-machines/security-skills
آخر نشاط في المصدر
٣ أغسطس ٢٠٢٦ في ١٩:٠٤
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
١٢
التفرعات
١

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.

عرض SKILL.md

SKILL.md
تعليمات المصدر · معاينة للقراءة فقط
name
experimentersoftroll422-security-loader
description
Windows filesystem security monitoring, access control, and encryption workflow integration using EaseFilter SDK with Rust bindings
triggers
["how do I monitor file activity on Windows with experimentersoftroll422","set up file access policies with experimentersoftroll422 security loader","integrate EaseFilter SDK with Rust bindings for filesystem security","configure encryption workflows in experimentersoftroll422","implement Windows file monitoring and access control","troubleshoot experimentersoftroll422 filesystem security issues","use experimentersoftroll422 for file policy enforcement","create Windows filesystem security rules with experimentersoftroll422"]
# experimentersoftroll422-security-loader > Skill by [ara.so](https://ara.so) — Security Skills collection. ## Overview Experimentersoftroll422 Security Loader is a Windows filesystem security project that provides file activity monitoring, access policy enforcement, and encryption workflow support through Rust bindings to the EaseFilter File Security SDK. It enables developers to build custom filesystem security solutions for Windows environments with policy-based file access control. ## Installation ### Prerequisites - Windows operating system - Rust toolchain (rustc, cargo) - EaseFilter File Security SDK - Administrator privileges for filesystem monitoring operations ### Clone and Setup ```bash git clone https://github.com/tomw286/experimentersoftroll422-security-loader.git cd experimentersoftroll422-security-loader ``` ### Rust Dependencies Add to your `Cargo.toml`: ```toml [dependencies] easefilter-sdk = "0.1" # Adjust version based on SDK binding winapi = { version = "0.3", features = ["fileapi", "winnt", "handleapi"] } serde = { version = "1.0", features = ["derive"] } toml = "0.5" log = "0.4" env_logger = "0.9" ``` ## Configuration ### Basic Configuration File Create `config.toml` in your project root: ```toml [filesystem] monitor_files = true control_access = true encryption = true log_level = "info" [monitoring] watched_paths = [ "C:\\Users\\*\\Documents", "C:\\ProgramData\\Sensitive" ] excluded_extensions = [".tmp", ".log"] real_time = true [access_control] enabled = true default_policy = "deny" audit_mode = false [encryption] enabled = true algorithm = "AES256" key_storage = "registry" [integration] runtime = "rust" sdk = "EaseFilter File Security SDK" sdk_path = "C:\\Program Files\\EaseFilter" ``` ### Loading Configuration ```rust use serde::Deserialize; use std::fs; #[derive(Debug, Deserialize)] struct FilesystemConfig { monitor_files: bool, control_access: bool, encryption: bool, log_level: String, } #[derive(Debug, Deserialize)] struct MonitoringConfig { watched_paths: Vec<String>, excluded_extensions: Vec<String>, real_time: bool, } #[derive(Debug, Deserialize)] struct AccessControlConfig { enabled: bool, default_policy: String, audit_mode: bool, } #[derive(Debug, Deserialize)] struct Config { filesystem: FilesystemConfig, monitoring: MonitoringConfig, access_control: AccessControlConfig, } fn load_config(path: &str) -> Result<Config, Box<dyn std::error::Error>> { let contents = fs::read_to_string(path)?; let config: Config = toml::from_str(&contents)?; Ok(config) } ``` ## Core API Usage ### Initializing the Security Loader ```rust use std::env; use log::{info, error}; struct SecurityLoader { config: Config, sdk_handle: Option<SDKHandle>, } impl SecurityLoader { fn new(config_path: &str) -> Result<Self, Box<dyn std::error::Error>> { env_logger::init(); let config = load_config(config_path)?; info!("Initializing Security Loader with config: {:?}", config); Ok(SecurityLoader { config, sdk_handle: None, }) } fn initialize_sdk(&mut self) -> Result<(), Box<dyn std::error::Error>> { let sdk_path = env::var("EASEFILTER_SDK_PATH") .unwrap_or_else(|_| "C:\\Program Files\\EaseFilter".to_string()); info!("Loading EaseFilter SDK from: {}", sdk_path); // Initialize SDK connection let handle = easefilter_sdk::initialize(&sdk_path)?; self.sdk_handle = Some(handle); info!("SDK initialized successfully"); Ok(()) } } ``` ### File Monitoring Setup ```rust use std::path::PathBuf; struct FileMonitor { watched_paths: Vec<PathBuf>, callback: Box<dyn Fn(FileEvent) + Send>, } #[derive(Debug, Clone)] enum FileEvent { Created(PathBuf), Modified(PathBuf), Deleted(PathBuf), Accessed(PathBuf), } impl FileMonitor { fn new(paths: Vec<String>) -> Self { let watched_paths = paths.into_iter() .map(PathBuf::from) .collect(); FileMonitor { watched_paths, callback: Box::new(|event| { info!("File event detected: {:?}", event); }), } } fn start(&self) -> Result<(), Box<dyn std::error::Error>> { info!("Starting file monitoring on {} paths", self.watched_paths.len()); for path in &self.watched_paths { self.register_path(path)?; } Ok(()) } fn register_path(&self, path: &PathBuf) -> Result<(), Box<dyn std::error::Error>> { info!("Registering monitor for: {:?}", path); // Register with EaseFilter SDK easefilter_sdk::register_monitor( path.to_str().unwrap(), FileEventMask::ALL, )?; Ok(()) } fn set_callback<F>(&mut self, callback: F) where F: Fn(FileEvent) + Send + 'static, { self.callback = Box::new(callback); } } ``` ### Access Control Policy Engine ```rust use std::collections::HashMap; #[derive(Debug, Clone, PartialEq)] enum AccessDecision { Allow, Deny, AuditAndAllow, AuditAndDeny, } struct AccessPolicy { rules: Vec<PolicyRule>, default: AccessDecision, } #[derive(Debug, Clone)] struct PolicyRule { path_pattern: String, allowed_operations: Vec<FileOperation>, denied_operations: Vec<FileOperation>, priority: u32, } #[derive(Debug, Clone, PartialEq)] enum FileOperation { Read, Write, Delete, Execute, Rename, } impl AccessPolicy { fn new(default: AccessDecision) -> Self { AccessPolicy { rules: Vec::new(), default, } } fn add_rule(&mut self, rule: PolicyRule) { self.rules.push(rule); self.rules.sort_by(|a, b| b.priority.cmp(&a.priority)); } fn evaluate(&self, path: &str, operation: &FileOperation) -> AccessDecision { for rule in &self.rules { if self.path_matches(&rule.path_pattern, path) { if rule.denied_operations.contains(operation) { return AccessDecision::Deny; } if rule.allowed_operations.contains(operation) { return AccessDecision::Allow; } } } self.default.clone() } fn path_matches(&self, pattern: &str, path: &str) -> bool { // Simplified wildcard matching if pattern.contains('*') { let pattern_parts: Vec<&str> = pattern.split('*').collect(); let mut pos = 0; for (i, part) in pattern_parts.iter().enumerate() { if i == 0 && !part.is_empty() && !path.starts_with(part) { return false; } if let Some(found_pos) = path[pos..].find(part) { pos += found_pos + part.len(); } else { return false; } } true } else { path == pattern } } } ``` ### Encryption Workflow Integration ```rust use std::io::{Read, Write}; use std::fs::File; struct EncryptionManager { algorithm: String, key: Vec<u8>, } impl EncryptionManager { fn new() -> Result<Self, Box<dyn std::error::Error>> { let key = Self::load_key_from_env()?; Ok(EncryptionManager { algorithm: "AES256".to_string(), key, }) } fn load_key_from_env() -> Result<Vec<u8>, Box<dyn std::error::Error>> { let key_b64 = env::var("ENCRYPTION_KEY")?; let key = base64::decode(key_b64)?; Ok(key) } fn encrypt_file(&self, path: &str) -> Result<(), Box<dyn std::error::Error>> { info!("Encrypting file: {}", path); let mut file = File::open(path)?; let mut contents = Vec::new(); file.read_to_end(&mut contents)?; let encrypted = self.encrypt_data(&contents)?; let mut output = File::create(format!("{}.encrypted", path))?; output.write_all(&encrypted)?; Ok(()) } fn decrypt_file(&self, path: &str) -> Result<Vec<u8>, Box<dyn std::error::Error>> { info!("Decrypting file: {}", path); let mut file = File::open(path)?; let mut contents = Vec::new(); file.read_to_end(&mut contents)?; self.decrypt_data(&contents) } fn encrypt_data(&self, data: &[u8]) -> Result<Vec<u8>, Box<dyn std::error::Error>> { // Integration with encryption SDK easefilter_sdk::encrypt(data, &self.key, &self.algorithm) } fn decrypt_data(&self, data: &[u8]) -> Result<Vec<u8>, Box<dyn std::error::Error>> { easefilter_sdk::decrypt(data, &self.key, &self.algorithm) } } ``` ## Complete Working Example ```rust use std::sync::{Arc, Mutex}; use std::thread; use std::time::Duration; fn main() -> Result<(), Box<dyn std::error::Error>> { // Load configuration let config = load_config("config.toml")?; // Initialize security loader let mut loader = SecurityLoader::new("config.toml")?; loader.initialize_sdk()?; // Set up file monitoring let monitor = Arc::new(Mutex::new( FileMonitor::new(config.monitoring.watched_paths.clone()) )); let monitor_clone = monitor.clone(); monitor.lock().unwrap().set_callback(move |event| { match event { FileEvent::Created(path) => { info!("New file created: {:?}", path); } FileEvent::Modified(path) => { info!("File modified: {:?}", path); } FileEvent::Accessed(path) => { info!("File accessed: {:?}", path); } FileEvent::Deleted(path) => { info!("File deleted: {:?}", path); } } }); monitor.lock().unwrap().start()?; // Set up access control let mut policy = AccessPolicy::new(AccessDecision::Deny); policy.add_rule(PolicyRule { path_pattern: "C:\\Users\\*\\Documents\\*.docx".to_string(),
عرض على GitHub
ملف SKILL.md هذا كبير جدا، لذلك يعرض SkillsMP القسم الاول فقط هنا. عرض على GitHub