From 9c8990a29721a4e3dc19da03107eb006b34b6eff Mon Sep 17 00:00:00 2001 From: Tobias Michalski Date: Mon, 14 Jun 2021 11:45:49 +0200 Subject: [PATCH 1/3] Condition for Outlook WebView URL Registry Change --- sysmonconfig-export.xml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index f4acf26..f004170 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -647,6 +647,7 @@ Microsoft\Office\Outlook\Addins\ Office Test\ + \Software\Microsoft\Office\;\Outlook\WebView\;URL Security\Trusted Documents\TrustRecords Internet Explorer\Toolbar\ @@ -701,6 +702,9 @@ regedit.exe \ + + + From 96209b3d28a1129fca258e2c9d29b8cf0d0e19a7 Mon Sep 17 00:00:00 2001 From: Tobias Michalski Date: Mon, 14 Jun 2021 11:51:28 +0200 Subject: [PATCH 2/3] Removed unnecessary whitespaces --- sysmonconfig-export.xml | 3 --- 1 file changed, 3 deletions(-) diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index f004170..5bf4e0e 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -702,9 +702,6 @@ regedit.exe \ - - - From d63e86fb17aaca5831ac6eb9676bb5979dcd9047 Mon Sep 17 00:00:00 2001 From: humpalum Date: Mon, 26 Jul 2021 09:39:36 +0200 Subject: [PATCH 3/3] Breaking the config --- sysmonconfig-export.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index 5bf4e0e..ec05cd2 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -80,7 +80,7 @@ code signatures to validate, but Sysmon does not support that. Look into AppLocker/WindowsDeviceGuard for whitelisting support. --> - + "C:\Windows\system32\wermgr.exe" "-queuereporting_svc" @@ -1157,4 +1157,4 @@ - \ No newline at end of file +