diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index ad46d59d..d25dc334 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -1,6 +1,6 @@ microsoft.com .microsoft.com + microsoft.com.akadns.net + microsoft.com.nsatc.net 23.4.43.27 72.21.91.29 - microsoft.com.akadns.net - .microsoft.com.nsatc.net 127.0.0.1 fe80:0:0:0 @@ -479,7 +479,7 @@ - + @@ -545,10 +545,13 @@ .job .pptm .ps1 + .sct .sys .scr .vbe .vbs + .wsc + .wsf .xlsm .ocx proj @@ -710,7 +713,7 @@ HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider HKLM\SYSTEM\CurrentControlSet\Control\Lsa\ - HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\ + HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders HKLM\Software\Microsoft\Netsh Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable @@ -729,6 +732,7 @@ Office Test\ \Software\Microsoft\Office\;\Outlook\WebView\;URL Security\Trusted Documents\TrustRecords + \EnableBHO Internet Explorer\Toolbar\ Internet Explorer\Extensions\ @@ -753,7 +757,7 @@ DisableRealtimeMonitoring \SubmitSamplesConsent HKLM\Software\Microsoft\Windows Defender\Exclusions - HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\ + HKLM\SOFTWARE\Policies\Microsoft\Windows Defender HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy @@ -773,6 +777,8 @@ HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress\(Default) HKLM\Software\Microsoft\Tracing\RASAPI32 HKLM\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\ + \Keyboard Layout\Preload + \Keyboard Layout\Substitutes \LowerCaseLongPath \Publisher @@ -885,15 +891,18 @@ .cmd .doc .hta + .jse .lnk .ppt .ps1 .ps2 .reg - .jse + .sct .vb .vbe .vbs + .wsc + .wsf :Zone.Identifier :newads