Views:

To monitor the created files, create a custom rule that targets the directory:

 
This rule might cause high number of alerts if the monitored directory is dynamic. Use it carefully.
  1. On the Deep Security console, go to Policies > Common Objects.
  2. Navigate to Rules > Integrity Monitoring Rules.
  3. Click New and select New Integrity Monitoring Rule.
  4. Go to Content tab.
  5. Choose File for Template.
  6. Enter the path on the Base Directory field.
  7. Enable the Include Sub Directories checkbox.
  8. On the section Include Files With Names Like, input asterisk (*) to match zero or more characters.
  9. Click Apply to save the new rule.

Content

Based on the sample above, it will detect any created files under the /test/ directory. The event will look similar to the following:

Tags