Skip to content

Commit 9f8d98c

Browse files
rabbitstackrabbitstack
authored andcommitted
fix(rules): Add CompatTelRunner.exe exclusion for Unusual process modified registry run key
1 parent e37d1a6 commit 9f8d98c

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

rules/persistence_unusual_process_modified_registry_run_key.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Unusual process modified registry run key
22
id: 921508a5-b627-4c02-a295-6c6863c0897b
3-
version: 1.0.2
3+
version: 1.0.3
44
description: |
55
Identifies an attempt by unusual Windows native processes to modify
66
the run key and gain persistence on users logons or machine reboots.
@@ -41,7 +41,8 @@ condition: >
4141
'?:\\Windows\\SysWOW64\\prevhost.exe',
4242
'?:\\Windows\\System32\\conhost.exe',
4343
'?:\\Windows\\System32\\taskhostw.exe',
44-
'?:\\Windows\\System32\\backgroundTaskHost.exe'
44+
'?:\\Windows\\System32\\backgroundTaskHost.exe',
45+
'?:\\Windows\\System32\\CompatTelRunner.exe'
4546
)
4647
4748
min-engine-version: 2.4.0

0 commit comments

Comments
 (0)