diff --git a/files/olafhartong-sysmonconfig.xml b/files/olafhartong-sysmonconfig.xml index d0b69ed..94f0855 100644 --- a/files/olafhartong-sysmonconfig.xml +++ b/files/olafhartong-sysmonconfig.xml @@ -1,4 +1,4 @@ - + * @@ -764,6 +764,9 @@ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports + HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging + HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging + HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates \Microsoft\SystemCertificates\Root\Certificates HKLM\SOFTWARE\Microsoft\Security Center\AllAlertsDisabled @@ -1220,7 +1223,35 @@ - + + + + + + + C:\Program Files\Mozilla Firefox\firefox.exe + C:\Program Files\Mozilla Firefox\updater.exe + C:\Program Files\Mozilla Firefox\default-browser-agent.exe + C:\Program Files\Mozilla Firefox\pingsender.exe + C:\Program Files\Git\cmd\git.exe + C:\Program Files\Git\mingw64\bin\git.exe + C:\Program Files\Git\mingw64\libexec\git-core\git.exe + C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe + + C:\Program Files (x86)\Microsoft\Edge\Application\ + \BHO\ie_to_edge_stub.exe + + + C:\Program Files (x86)\Microsoft\Edge\Application\ + \identity_helper.exe + + + C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\ + \MicrosoftEdge_X64_ + + unknown process + C:\Program Files\Microsoft VS Code\Code.exe + @@ -1251,7 +1282,10 @@ C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe "C:\Program Files\Microsoft Monitoring Agent\Agent\MonitoringHost.exe" -Embedding - C:\Windows\system32\cscript.exe" /nologo "MonitorKnowledgeDiscovery.vbs + + "C:\Program Files\Microsoft Monitoring Agent\Agent\MonitoringHost.exe" + C:\Windows\system32\cscript.exe" /nologo "MonitorKnowledgeDiscovery.vbs + C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe