Skip to content

Commit b3affb4

Browse files
author
Azure Pipeline
committed
Updated after successful CICD run 05/05/2022 13:49:54
1 parent 96832a6 commit b3affb4

1 file changed

Lines changed: 7 additions & 8 deletions

File tree

sysmonconfig.xml

Lines changed: 7 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1415,7 +1415,6 @@
14151415
<TargetObject name="technique_id=T1137.006,technique_name=Add-ins" condition="contains all">\Microsoft\Office;\Outlook\Addins</TargetObject>
14161416
<TargetObject name="technique_id=T1137.006,technique_name=Add-ins" condition="contains">\Software\Microsoft\VSTO\Security\Inclusion</TargetObject>
14171417
<TargetObject name="technique_id=T1137.006,technique_name=Add-ins" condition="contains">\Software\Microsoft\VSTO\SolutionMetadata</TargetObject>
1418-
<TargetObject name="technique_name=Outlook Server 95/98 Identity Keys" condition="contains">Identities</TargetObject>
14191418
<TargetObject condition="contains all">HKCU\SOFTWARE\Microsoft\Office\;\Outlook\Profiles\;\9375CFF0413111d3B88A00104B2A6676\;\Account Name</TargetObject>
14201419
<TargetObject condition="contains all">HKCU\SOFTWARE\Microsoft\Office\;\Outlook\Profiles\;\9375CFF0413111d3B88A00104B2A6676\;\Display Name</TargetObject>
14211420
<TargetObject condition="contains all">HKCU\SOFTWARE\Microsoft\Office\;\Outlook\Profiles\;\9375CFF0413111d3B88A00104B2A6676\;\Email</TargetObject>
@@ -1443,13 +1442,13 @@
14431442
<TargetObject condition="contains">software\microsoft\Office test\special\perf\</TargetObject>
14441443
<TargetObject condition="contains all">hkcu\software\microsoft\office\;\Options\OPEN</TargetObject>
14451444
<TargetObject name="technique_id=T1137.006,technique_name=Add-ins" condition="contains all">\Microsoft\Office;\PowerPoint\Addins</TargetObject>
1446-
<TargetObject name="T1559.002,office" condition="end with">\Word\Security\AllowDDE</TargetObject>
1447-
<TargetObject name="T1559.002,office" condition="end with">\Excel\Security\DisableDDEServerLaunch</TargetObject>
1448-
<TargetObject name="T1559.002,office" condition="end with">\Excel\Security\DisableDDEServerLookup</TargetObject>
1449-
<TargetObject name="T1562,office" condition="end with">\VBAWarnings</TargetObject>
1450-
<TargetObject name="T1562,office" condition="end with">\DisableInternetFilesInPV</TargetObject>
1451-
<TargetObject name="T1562,office" condition="end with">\DisableUnsafeLocationsInPV</TargetObject>
1452-
<TargetObject name="T1562,office" condition="end with">\DisableAttachementsInPV</TargetObject>
1445+
<TargetObject name="T1559.002,technique_name=Dynamic Data Exchange" condition="end with">\Word\Security\AllowDDE</TargetObject>
1446+
<TargetObject name="T1559.002,technique_name=Dynamic Data Exchange" condition="end with">\Excel\Security\DisableDDEServerLaunch</TargetObject>
1447+
<TargetObject name="T1559.002,technique_name=Dynamic Data Exchange" condition="end with">\Excel\Security\DisableDDEServerLookup</TargetObject>
1448+
<TargetObject name="T1562.001,technique_name=Disable or Modify Tools" condition="end with">\VBAWarnings</TargetObject>
1449+
<TargetObject name="T1562.001,technique_name=Disable or Modify Tools" condition="end with">\DisableInternetFilesInPV</TargetObject>
1450+
<TargetObject name="T1562.001,technique_name=Disable or Modify Tools" condition="end with">\DisableUnsafeLocationsInPV</TargetObject>
1451+
<TargetObject name="T1562.001,technique_name=Disable or Modify Tools" condition="end with">\DisableAttachementsInPV</TargetObject>
14531452
<TargetObject name="technique_id=T1021.001,technique_name=Remote Desktop Protocol" condition="is">HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\MaxInstanceCount</TargetObject>
14541453
<TargetObject name="technique_id=T1021.001,technique_name=Remote Desktop Protocol" condition="is">HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\RaunSolicit</TargetObject>
14551454
<TargetObject name="technique_id=T1112,technique_name=Modify Registry" condition="begin with">HKLM\SYSTEM\CurrentControlSet\services\TermService\Parameters\ServiceDll</TargetObject>

0 commit comments

Comments
 (0)