fix: default to (Default)
This commit is contained in:
@@ -19,7 +19,7 @@ detection:
|
||||
TargetObject|startswith:
|
||||
- 'HKCR\CLSID\'
|
||||
- 'HKCU\Software\Classes\CLSID\'
|
||||
TargetObject|endswith: \InprocServer32\default
|
||||
TargetObject|endswith: '\InprocServer32\(Default)'
|
||||
filter1:
|
||||
Details|contains: # Exclude privileged directories and observed FPs
|
||||
- '%%systemroot%%\system32\'
|
||||
|
||||
Reference in New Issue
Block a user