Rust language demo crates for the EaseFilter File Security SDK. Includes the following features:
-
Monitoring of file/folder access
-
Control of file/folder access
-
Filesystem-level encryption of specific folders and files
-
Monitoring of the Windows Registry
-
Monitoring of specific processes
The crate easefilter-sys has direct bindings generated using bindgen,
and the easefilter crate provides a higher level interface.
Note
A license key is required to use this program. Contact EaseFilter support by e-mail for a trial key.
If you run cargo check or cargo clippy, always run them specifically with
-p easefilter, to avoid recompiling easefilter-sys.
Multiple Rust examples that use the bindings are provided in the
easefilter/examples/ folder. To run an example, use the command:
cargo run --example <example name>
Note
Run from an elevated prompt (administrator) since the EaseFilter driver
requires it. Your license key is read from the EASEFILTER_TEST_LICENSE_KEY
environment variable.
monitor_dir — Monitor a directory for file-system events (create, delete,
rename, write). Logs each event with user SID, account name, and process info.
cargo run --example monitor_dir -- "C:\path\to\watch"
control_static — Deny write and delete at the driver level via
AccessFlag. Operations are rejected at the driver level.
cargo run --example control_static -- "C:\path\to\protect"
control_dynamic — Userspace callback code inspects every pre-operation
I/O event and dynamically denies renames and deletes.
cargo run --example control_dynamic -- "C:\path\to\protect"
encrypt_static — Transparent encryption with a static AES-256 key derived
from a passphrase via Argon2id. The key is embedded in the rule at install time.
cargo run --example encrypt_static -- "C:\path\to\protect" "my passphrase"
encrypt_callback — Transparent encryption where every encrypt/decrypt
request fires a userspace event to dynamically supply the key.
cargo run --example encrypt_callback -- "C:\path\to\protect"
Files created in the protected directory will be encrypted at rest on the disk, and decrypted whenever the filter rule is active.
process_monitor — Monitor process/thread creation and termination events
for a given executable or glob pattern. This invocation monitors all
notepad.exe processes.
cargo run --example process_monitor -- "C:\Windows\System32\notepad.exe"
process_control_static — Block a specific executable from launching at
the driver level. The following command prevents notepad.exe from starting:
cargo run --example process_control_static -- "C:\Windows\System32\notepad.exe"
process_control_dynamic — Allow or deny process creation dynamically. The
following command prevents cmd.exe from starting when it has rmdir in its
arguments:
cargo run --example process_control_dynamic -- "C:\Windows\System32\cmd.exe" "rmdir"
registry_monitor — Monitor registry key operations (create, delete, set
value, rename, open). Logs each event with the key path, user SID, and process
info. The key mask is a glob pattern.
cargo run --example registry_monitor -- "*\EasefilterRust\*"
registry_control_static — Deny specific registry operations at the driver
level via RegControlFlag. The key mask is a glob pattern.
cargo run --example registry_control_static -- "*\EasefilterRust\*"
registry_control_dynamic — Userspace callback code inspects every
registry pre-operation event and dynamically denies keys whose path contains
"deny". The key mask is a glob pattern.
cargo run --example registry_control_dynamic -- "*\EasefilterRust\*"
| Product Name | Description |
|---|---|
| Cloud File System SDK | EaseFilter Cloud File System SDK Introduction. |
| CloudTier Storage Tiering SDK | EaseFilter Storage Tiering Filter Driver SDK Introduction. |
| File Monitor SDK | EaseFilter File Monitor Filter Driver SDK Introduction. |
| File Control SDK | EaseFilter File Control Filter Driver SDK Introduction. |
| File Encryption SDK | EaseFilter Transparent File Encryption Filter Driver SDK Introduction. |
| Registry Filter SDK | EaseFilter Registry Filter Driver SDK Introduction. |
| Process Filter SDK | EaseFilter Process Filter Driver SDK Introduction. |
| EaseFilter SDK Programming | EaseFilter Filter Driver SDK Programming. |
| Sample Project | Description |
|---|---|
| CloudTier Storage Tiering Demo | A HSM File System Filter Driver Demo. |
| CloudTier S3 Tiering Demo | CloudTier S3 Intelligent Tiering Demo. |
| Cloud File DR S3 Demo | Cloud File DR S3 Demo. |
| Amazon S3 File Explorer Demo | Amazon S3 File Explorer Demo. |
| Auto File DRM Encryption | Auto file encryption with DRM data embedded. |
| Transparent File Encrypt | Transparent on access file encryption. |
| Secure File Sharing with DRM | Secure encrypted file sharing with digital rights management. |
| File Monitor Example | Monitor file system I/O in real time, tracking file changes. |
| File Protector Example | Prevent sensitive files from being accessed by unauthorized users or processes. |
| FolderLocker Example | Lock file automatically in a FolderLocker. |
| Process Monitor | Monitor the process creation and termination, block unauthorized process running. |
| Registry Monitor | Monitor the Registry activities, block the modification of the Registry keys. |
| Secure Sandbox Example | A secure sandbox example, block the processes accessing the files out of the box. |
| FileSystemWatcher Example | File system watcher, logging the file I/O events. |
| ZeroTrust Example | Zero trust file acc |
| ess control with encryption feature. |
- Understand MiniFilter Driver
- Understand File I/O
- Understand I/O Request Packets(IRPs)
- Filter Driver Developer Guide
- MiniFilter Filter Driver Framework
- Isolation Filter Driver
If you have questions or need help, please contact support@easefilter.com