Skip to content

Commit 18cc9f3

Browse files
committed
Added CompatTelRunner.exe as an exclusion to persistence_unusual_process_modified_registry_run_key.yml
1 parent 0ad20b2 commit 18cc9f3

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

rules/persistence_unusual_process_modified_registry_run_key.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,8 @@ condition: >
4343
'?:\\Windows\\SysWOW64\\prevhost.exe',
4444
'?:\\Windows\\System32\\conhost.exe',
4545
'?:\\Windows\\System32\\taskhostw.exe',
46-
'?:\\Windows\\System32\\backgroundTaskHost.exe'
46+
'?:\\Windows\\System32\\backgroundTaskHost.exe',
47+
'?:\\Windows\\System32\\CompatTelRunner.exe'
4748
)
4849
4950
min-engine-version: 2.4.0

0 commit comments

Comments
 (0)