File tree Expand file tree Collapse file tree 1 file changed +3
-0
lines changed
Expand file tree Collapse file tree 1 file changed +3
-0
lines changed Original file line number Diff line number Diff line change 846846 <TargetObject condition =" contains" >\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\</TargetObject >
847847 <TargetObject condition =" contains" >\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths\</TargetObject >
848848 <TargetObject condition =" begin with" >HKLM\SYSTEM\CurrentControlSet\services\DNS\Parameters\</TargetObject > <!-- Microsoft:Windows:DNS: ServerLevelPluginDll Issue https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83 -->
849+ <!-- Testing - Unknown log volume but relevant registry keys -->
850+ <TargetObject condition =" begin with" >HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_</TargetObject > <!-- Often used by malware -->
851+ <TargetObject condition =" begin with" >HKLM\SYSTEM\CurrentControlSet\Services\</TargetObject > <!-- Windows Services -->
849852 </RegistryEvent >
850853 </RuleGroup >
851854
You can’t perform that action at this time.
0 commit comments