mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Remove additional backlash
This commit is contained in:
parent
acff5ef4f9
commit
1e640b50f9
@ -19,8 +19,8 @@ detection:
|
||||
TargetObject: 'HKU\\*_Classes\CLSID\\*\InProcServer32\(Default)'
|
||||
filter:
|
||||
Details|contains: # Exclude privileged directories and observed FPs
|
||||
- '%%systemroot%%\system32\\'
|
||||
- '%%systemroot%%\SysWow64\\'
|
||||
- '%%systemroot%%\system32\'
|
||||
- '%%systemroot%%\SysWow64\'
|
||||
- '\AppData\Local\Microsoft\OneDrive\\*\FileCoAuthLib64.dll'
|
||||
- '\AppData\Local\Microsoft\OneDrive\\*\FileSyncShell64.dll'
|
||||
- '\AppData\Local\Microsoft\TeamsMeetingAddin\\*\Microsoft.Teams.AddinLoader.dll'
|
||||
|
Loading…
Reference in New Issue
Block a user