diff --git a/10_process_access/include_office_process_creation.xml b/10_process_access/include_office_process_creation.xml new file mode 100644 index 00000000..52060bbe --- /dev/null +++ b/10_process_access/include_office_process_creation.xml @@ -0,0 +1,14 @@ + + + * + + + + + C:\Program Files;\Microsoft Office\Root\Office + C:\Windows\System32\KERNELBASE.dll+76516 + + + + + diff --git a/12_13_14_registry_event/include_windows_secureboot.xml b/12_13_14_registry_event/include_windows_secureboot.xml new file mode 100644 index 00000000..d72ec147 --- /dev/null +++ b/12_13_14_registry_event/include_windows_secureboot.xml @@ -0,0 +1,11 @@ + + + * + + + + HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot\State + + + + diff --git a/17_18_pipe_event/include_psexec.xml b/17_18_pipe_event/include_psexec.xml index ab19452d..062779b1 100644 --- a/17_18_pipe_event/include_psexec.xml +++ b/17_18_pipe_event/include_psexec.xml @@ -3,7 +3,11 @@ \PSEXESVC + + ADMIN$;C$;IPC$ + .exe;.dll + - \ No newline at end of file + diff --git a/7_image_load/exclude_zoom.xml b/7_image_load/exclude_zoom.xml new file mode 100644 index 00000000..3f4a9d8a --- /dev/null +++ b/7_image_load/exclude_zoom.xml @@ -0,0 +1,20 @@ + + + * + + + + + C:\Users\;\AppData\Roaming\Zoom\bin\;dll + C:\Windows\System32\ + Zoom Video Communications + + + C:\Users\;\AppData\Roaming\Zoom\bin\;dll + C:\Users\;\AppData\Roaming\Zoom\bin\;exe + Zoom Video Communications + + + + +