From 716621879604802b1f13f8a4229e0741b404135d Mon Sep 17 00:00:00 2001 From: Tran Trung Hieu Date: Mon, 18 Oct 2021 09:25:22 +0400 Subject: [PATCH] Update the Antivirus Tampering configuration, using broader condition --- sysmonconfig-export.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index 028d3738..0fdf3e85 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -301,7 +301,7 @@ net1.exe notepad.exe nslookup.exe - powershell.exe + powershell.exe powershell_ise.exe qprocess.exe qwinsta.exe @@ -694,7 +694,7 @@ \SpynetReporting DisableRealtimeMonitoring \SubmitSamplesConsent - HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\ + HKLM\SOFTWARE\Policies\Microsoft\Windows Defender HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy