We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 63625bf commit d1e6b21Copy full SHA for d1e6b21
12_13_14_registry_event/exclude_windows_misc.xml
@@ -33,6 +33,12 @@
33
<Image condition="is">C:\Windows\system32\lsass.exe</Image>
34
<TargetObject condition="contains">HKLM\System\CurrentControlSet\Services</TargetObject>
35
</Rule>
36
+ <Rule groupRelation="and">
37
+ <TargetObject condition="contains">SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization</TargetObject>
38
+ <Image condition="is">C:\Windows\System32\svchost.exe</Image>
39
+ </Rule>
40
+ <TargetObject condition="is">HKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTime</TargetObject>
41
+ <TargetObject condition="is">HKLM\System\CurrentControlSet\Services\SmsRouter\State\Registration\Ids</TargetObject>
42
</RegistryEvent>
43
</RuleGroup>
44
</EventFiltering>
0 commit comments