fix: default to (Default)

This commit is contained in:
Florian Roth 2021-09-16 11:39:45 +02:00 committed by GitHub
parent 6e981f56df
commit a926439b39
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -19,7 +19,7 @@ detection:
TargetObject|startswith:
- 'HKCR\CLSID\'
- 'HKCU\Software\Classes\CLSID\'
TargetObject|endswith: \InprocServer32\default
TargetObject|endswith: '\InprocServer32\(Default)'
filter1:
Details|contains: # Exclude privileged directories and observed FPs
- '%%systemroot%%\system32\'