From cfabbc4bdfcb523c2b5b7c79afd02fe12159490c Mon Sep 17 00:00:00 2001 From: securepeacock <92804416+securepeacock@users.noreply.github.com> Date: Wed, 15 Jun 2022 10:51:15 -0400 Subject: [PATCH] Update registry_set_enabling_turn_off_check.yml --- .../registry_set/registry_set_enabling_turn_off_check.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/registry/registry_set/registry_set_enabling_turn_off_check.yml b/rules/windows/registry/registry_set/registry_set_enabling_turn_off_check.yml index 748e8c552..41e31442e 100644 --- a/rules/windows/registry/registry_set/registry_set_enabling_turn_off_check.yml +++ b/rules/windows/registry/registry_set/registry_set_enabling_turn_off_check.yml @@ -13,7 +13,7 @@ detection: selection: EventType: SetValue TargetObject: - - 'HKLM\SOFTWARE\Policies\Microsoft\Windows\ScriptedDiagnostics + - 'HKLM\SOFTWARE\Policies\Microsoft\Windows\ScriptedDiagnostics' Details: 'DWORD (0x00000001)' condition: selection falsepositives: