|
28 | 28 | "^HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\Services\\\\mpssvc\\\\Parameterss", |
29 | 29 | "^HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\Services\\\\PolicyAgent\\\\Parameters", |
30 | 30 | "^HKEY_CURRENT_USER\\\\System\\\\CurrentControlSet\\\\Control\\\\DeviceContainers\\\\", |
31 | | - "^HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\WOW6432Node\\\\Microsoft\\\\EAPSIMMethods" |
| 31 | + "^HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\WOW6432Node\\\\Microsoft\\\\EAPSIMMethods", |
| 32 | + "^HKEY_LOCAL_MACHINE\\\\SECURITY", |
| 33 | + "^HKEY_LOCAL_MACHINE\\\\SAM", |
| 34 | + "^HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\Microsoft\\\\EAPSIMMethods", |
| 35 | + "^HKEY_USERS\\\\S-[0-9-]*\\\\System\\\\CurrentControlSet\\\\Control\\\\DeviceContainers", |
| 36 | + "^HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\Services\\\\ADOVMPPackage", |
| 37 | + "^HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\Services\\\\BTHPORT\\\\Parameters", |
| 38 | + "^HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\ControlSet001\\\\Services\\\\mpssvc\\\\Parameters", |
| 39 | + "^HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\CurrentControlSet\\\\Services\\\\ADOVMPPackage", |
| 40 | + "^HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\CurrentControlSet\\\\Services\\\\BTHPORT\\\\Parameters", |
| 41 | + "^HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\CurrentControlSet\\\\Services\\\\PolicyAgent\\\\Parameters" |
32 | 42 | ] |
33 | 43 | }, |
34 | 44 | "Hive": { |
|
67 | 77 | "^[A-Z]:\\\\Windows\\\\Temp\\\\MpCmdRun.log$", |
68 | 78 | "^[A-Z]:\\\\Windows\\\\Temp\\\\MpSigStub.log$", |
69 | 79 | "^[A-Z]:\\\\Windows\\\\System32\\\\LogFiles\\\\WMI\\\\LwtNetLog.etl$", |
70 | | - "^[A-Z]:\\\\ProgramData\\\\Microsoft\\\\Windows Defender\\\\Support\\\\MpWppTracing$" |
| 80 | + "^[A-Z]:\\\\ProgramData\\\\Microsoft\\\\Windows Defender\\\\Support\\\\MpWppTracing$", |
| 81 | + "^[A-Z]:\\\\Windows\\\\CCM\\\\ScriptStore", |
| 82 | + "^[A-Z]:\\\\ProgramData\\\\Microsoft\\\\Windows\\\\Containers\\\\BaseImages\\\\.*?\\\\Files\\\\System Volume Information" |
71 | 83 | ] |
72 | 84 | } |
73 | 85 | } |
|
0 commit comments