File tree Expand file tree Collapse file tree 1 file changed +4
-0
lines changed Expand file tree Collapse file tree 1 file changed +4
-0
lines changed Original file line number Diff line number Diff line change 87
87
<Image condition =" is" >C:\Windows\System32\plasrv.exe</Image > <!-- Microsoft:Windows: Performance Logs and Alerts DCOM Server-->
88
88
<Image condition =" is" >C:\Windows\System32\wifitask.exe</Image > <!-- Microsoft:Windows: Wireless Background Task-->
89
89
<Image condition =" is" >C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe</Image > <!-- Microsoft:Windows: Touch Keyboard and Handwriting Panel Helper-->
90
+ <Image condition =" is" >C:\Windows\System32\smartscreen.exe</Image > <!-- Microsoft:Windows: Smartscreen, checks malicious websites and files https://www.howtogeek.com/320711/what-is-smartscreen-and-why-is-it-running-on-my-pc/ -->
91
+ <Image condition =" is" >C:\Windows\System32\msfeedssync.exe</Image > <!-- Microsoft:Windows: Microsoft Feeds Synchronization https://superuser.com/questions/445995/msfeedssync-exe-what-does-it-do -->
92
+ <Image condition =" is" >C:\Windows\System32\RuntimeBroker.exe</Image > <!-- Microsoft:Windows: Runtime Broker https://www.howtogeek.com/268240/what-is-runtime-broker-and-why-is-it-running-on-my-pc/ -->
90
93
<Image condition =" is" >C:\Windows\System32\TokenBrokerCookies.exe</Image > <!-- Microsoft:Windows: SSO sign-in assistant for MicrosoftOnline.com-->
91
94
<CommandLine condition =" is" >C:\windows\system32\wermgr.exe -queuereporting</CommandLine > <!-- Microsoft:Windows:Windows error reporting/telemetry-->
92
95
<ParentCommandLine condition =" is" >C:\windows\system32\wermgr.exe -queuereporting</ParentCommandLine > <!-- Microsoft:Windows:Windows error reporting/telemetry-->
147
150
<CommandLine condition =" is" >C:\Windows\system32\svchost.exe -k netsvcs -s CertPropSvc</CommandLine >
148
151
<CommandLine condition =" is" >C:\Windows\system32\svchost.exe -k netsvcs -s DsmSvc</CommandLine >
149
152
<CommandLine condition =" is" >C:\Windows\system32\svchost.exe -k netsvcs -s Gpsvc</CommandLine > <!-- Microsoft:Windows:Network: Group Policy -->
153
+ <CommandLine condition =" is" >C:\Windows\System32\svchost.exe -k netsvcs -p -s NetSetupSvc</CommandLine > <!-- Microsoft:Windows: Network Setup Service, manages the installation of network drivers -->
150
154
<CommandLine condition =" is" >C:\Windows\system32\svchost.exe -k netsvcs -s ProfSvc</CommandLine > <!-- Microsoft:Windows: Network services-->
151
155
<CommandLine condition =" is" >C:\Windows\system32\svchost.exe -k netsvcs -s SENS</CommandLine > <!-- Microsoft:Windows: Network services-->
152
156
<CommandLine condition =" is" >C:\Windows\system32\svchost.exe -k netsvcs -s SessionEnv</CommandLine > <!-- Microsoft:Windows: Network services-->
You can’t perform that action at this time.
0 commit comments