What does IH-INT-002 flag?
Reports a file or a whole skill folder that appeared after the baseline was created.
- A path under a watched folder that is not in the baseline.
- Reported by verify only.
Why it matters
New files are where a dropped payload or an installed skill you did not expect would show up.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-INT-002 fire on a safe skill?
- Skills you installed on purpose since the last baseline.
How do I fix an IH-INT-002 finding?
- Inspect the new file before trusting the skill.
- Update the baseline once you accept it.
CLI guidance: Inspect the new file before trusting the skill, then update the baseline if you accept it.
How do I tune or allow IH-INT-002?
Run ironheights baseline update after you accept the new files.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-INT-002.
What can IH-INT-002 miss?
- Files outside the watched folders.
- Whether the new file is harmful; scan it to find out.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.