From 31391b5c922543b771700019cb778ba8940f7cc1 Mon Sep 17 00:00:00 2001
From: tulsec <55816757+tulsec@users.noreply.github.com>
Date: Fri, 5 Mar 2021 23:14:27 -0600
Subject: [PATCH] Update sysmonconfig-export.xml
---
sysmonconfig-export.xml | 24 ++++++++++++------------
1 file changed, 12 insertions(+), 12 deletions(-)
diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml
index f4acf26c..90208011 100644
--- a/sysmonconfig-export.xml
+++ b/sysmonconfig-export.xml
@@ -150,8 +150,8 @@
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s TabletInputService
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s UmRdpService
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WPDBusEnum
- C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s NgcSvc
- C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -p -s NgcCtnrSvc
+ C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s NgcSvc
+ C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -p -s NgcCtnrSvc
C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SCardSvr
C:\Windows\system32\svchost.exe -k netsvcs -p -s wuauserv
C:\Windows\System32\svchost.exe -k netsvcs -p -s SessionEnv
@@ -226,7 +226,7 @@
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=
-
+
@@ -259,7 +259,7 @@
-
+
@@ -332,7 +332,7 @@
3389
5800
5900
- 444
+ 4444
1080
3128
@@ -808,7 +808,7 @@
-
+
@@ -991,7 +991,7 @@
.criteo.net
.crwdcntrl.net
.demdex.net
- .domdex.com
+ .domdex.com
.dotomi.com
.doubleclick.net
.doubleverify.com
@@ -1102,7 +1102,7 @@
-
@@ -1119,7 +1119,7 @@
-
+
-
+
-
+
-
\ No newline at end of file
+