Remove additional backlash

This commit is contained in:
Jonhnathan 2020-11-20 01:58:20 -03:00 committed by GitHub
parent acff5ef4f9
commit 1e640b50f9
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -19,8 +19,8 @@ detection:
TargetObject: 'HKU\\*_Classes\CLSID\\*\InProcServer32\(Default)'
filter:
Details|contains: # Exclude privileged directories and observed FPs
- '%%systemroot%%\system32\\'
- '%%systemroot%%\SysWow64\\'
- '%%systemroot%%\system32\'
- '%%systemroot%%\SysWow64\'
- '\AppData\Local\Microsoft\OneDrive\\*\FileCoAuthLib64.dll'
- '\AppData\Local\Microsoft\OneDrive\\*\FileSyncShell64.dll'
- '\AppData\Local\Microsoft\TeamsMeetingAddin\\*\Microsoft.Teams.AddinLoader.dll'