Skip to content

Commit d1e6b21

Browse files
authored
filter additional noise
1 parent 63625bf commit d1e6b21

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

Diff for: 12_13_14_registry_event/exclude_windows_misc.xml

+6
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,12 @@
3333
<Image condition="is">C:\Windows\system32\lsass.exe</Image>
3434
<TargetObject condition="contains">HKLM\System\CurrentControlSet\Services</TargetObject>
3535
</Rule>
36+
<Rule groupRelation="and">
37+
<TargetObject condition="contains">SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization</TargetObject>
38+
<Image condition="is">C:\Windows\System32\svchost.exe</Image>
39+
</Rule>
40+
<TargetObject condition="is">HKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTime</TargetObject>
41+
<TargetObject condition="is">HKLM\System\CurrentControlSet\Services\SmsRouter\State\Registration\Ids</TargetObject>
3642
</RegistryEvent>
3743
</RuleGroup>
3844
</EventFiltering>

0 commit comments

Comments
 (0)