mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
fix: default
to (Default)
This commit is contained in:
parent
6e981f56df
commit
a926439b39
@ -19,7 +19,7 @@ detection:
|
||||
TargetObject|startswith:
|
||||
- 'HKCR\CLSID\'
|
||||
- 'HKCU\Software\Classes\CLSID\'
|
||||
TargetObject|endswith: \InprocServer32\default
|
||||
TargetObject|endswith: '\InprocServer32\(Default)'
|
||||
filter1:
|
||||
Details|contains: # Exclude privileged directories and observed FPs
|
||||
- '%%systemroot%%\system32\'
|
||||
|
Loading…
Reference in New Issue
Block a user