Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Line 239 registry formatting #179

Open
wants to merge 210 commits into
base: master
Choose a base branch
from

Conversation

kevinelwell
Copy link

Created issue 48

Change line 239 from:
<TargetObject condition="is">\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft Print to PDF\PrinterDriverData</TargetObject>

to:
<TargetObject condition="is">HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft Print to PDF\PrinterDriverData</TargetObject>

Neo23x0 and others added 30 commits July 24, 2021 08:22
This was necessary to allow us to 1. merge all open pull request of the original repo AND 2. allow our new repository to receive new pull requests
Added a workflow that installs sysmon with the config and fails when sysmon has an error
Also changed the numbers to allow up to about 5% of more events
Process Access Config für lsass.exe and CobaltStrike BOF
New CobaltStrike NamedPipes
nasbench and others added 30 commits February 10, 2023 00:05
feat: add onenote app to blocklist
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
feat: add new entries and resolve multiple issues
feat: remove duplicate rules
feat: add vmware conf path
adding EDRSandblast itself (not just the drivers used by it)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet