Usage: /bin/secpolicytools -r|--reset Reset all policy rules. -p|--load-policy[policy dir] Load a predefined policy. A default dir of /etc/vmware/secpolicy will be used. -d|--display-policy Display the current policy. -D|--lookup-domain Lookup the value of a domain label. -O|--lookup-object Lookup the value of an object label. -l|--list-labels List all valid domains and objects -k|--keywords List all policy keywords. -g|--get-label Get the object label for a file. -s|--set-label -L|--label Set the object label for a file. -T|--set-tag -L|--label Add VMCI service access to privileged VM with label. -N|--new-dom Create domain for privileged VM with label. -C|--del-dom Delete domain for privileged VM with label. -h|--help Show this message. There are additional options in esxcli system secpolicy.