Add more TaskName

This commit is contained in:
frack113
2023-01-13 13:06:02 +01:00
parent 80be90c331
commit 5d0b0f6663
@@ -22,8 +22,13 @@ detection:
selection:
EventID: 141
TaskName|contains:
- '\Microsoft\Windows\Windows Defender\'
- '\Microsoft\Windows\WindowsUpdate\'
- '\Windows\SystemRestore\SR'
- '\Windows\Windows Defender\'
- '\Windows\BitLocker'
- '\Windows\WindowsBackup\'
- '\Windows\WindowsUpdate\'
- '\Windows\UpdateOrchestrator\'
- '\Windows\ExploitGuard'
filter:
UserName|contains:
- 'AUTHORI'