fix: default to (Default)

This commit is contained in:
Florian Roth
2021-09-16 11:39:45 +02:00
committed by GitHub
parent 6e981f56df
commit a926439b39
@@ -19,7 +19,7 @@ detection:
TargetObject|startswith:
- 'HKCR\CLSID\'
- 'HKCU\Software\Classes\CLSID\'
TargetObject|endswith: \InprocServer32\default
TargetObject|endswith: '\InprocServer32\(Default)'
filter1:
Details|contains: # Exclude privileged directories and observed FPs
- '%%systemroot%%\system32\'