Replace start of paths with placeholders

This commit is contained in:
Ryan Plas 2020-10-17 09:36:25 -04:00
parent 53f0261a62
commit ff84852803

View File

@ -17,8 +17,8 @@ detection:
EventID: 4663
AccessList|contains: '%%4416'
ObjectName|endswith:
- '\{641ECF7F-6AC4-4A63-BF85-DFDE140E9F89}\Machine\Preferences\Groups\Groups.xml'
- '\Panther\Unattend.xml'
- '\%POLICY_ID%\Machine\Preferences\Groups\Groups.xml'
- '\%FOLDER_NAME%\Unattend.xml'
condition: selection
fields:
- EventID