diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index 028d3738..0fdf3e85 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -301,7 +301,7 @@ net1.exe notepad.exe nslookup.exe - powershell.exe + powershell.exe powershell_ise.exe qprocess.exe qwinsta.exe @@ -694,7 +694,7 @@ \SpynetReporting DisableRealtimeMonitoring \SubmitSamplesConsent - HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\ + HKLM\SOFTWARE\Policies\Microsoft\Windows Defender HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy