From 31391b5c922543b771700019cb778ba8940f7cc1 Mon Sep 17 00:00:00 2001 From: tulsec <55816757+tulsec@users.noreply.github.com> Date: Fri, 5 Mar 2021 23:14:27 -0600 Subject: [PATCH] Update sysmonconfig-export.xml --- sysmonconfig-export.xml | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index f4acf26c..90208011 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -150,8 +150,8 @@ C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s TabletInputService C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s UmRdpService C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WPDBusEnum - C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s NgcSvc - C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -p -s NgcCtnrSvc + C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s NgcSvc + C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -p -s NgcCtnrSvc C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SCardSvr C:\Windows\system32\svchost.exe -k netsvcs -p -s wuauserv C:\Windows\System32\svchost.exe -k netsvcs -p -s SessionEnv @@ -226,7 +226,7 @@ "C:\Program Files\Google\Chrome\Application\chrome.exe" --type= - + @@ -259,7 +259,7 @@ - + @@ -332,7 +332,7 @@ 3389 5800 5900 - 444 + 4444 1080 3128 @@ -808,7 +808,7 @@ - + @@ -991,7 +991,7 @@ .criteo.net .crwdcntrl.net .demdex.net - .domdex.com + .domdex.com .dotomi.com .doubleclick.net .doubleverify.com @@ -1102,7 +1102,7 @@ - @@ -1119,7 +1119,7 @@ - + - + - + - \ No newline at end of file +