diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index f4acf26c..ec05cd2f 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -80,7 +80,7 @@ code signatures to validate, but Sysmon does not support that. Look into AppLocker/WindowsDeviceGuard for whitelisting support. --> - + "C:\Windows\system32\wermgr.exe" "-queuereporting_svc" @@ -647,6 +647,7 @@ Microsoft\Office\Outlook\Addins\ Office Test\ + \Software\Microsoft\Office\;\Outlook\WebView\;URL Security\Trusted Documents\TrustRecords Internet Explorer\Toolbar\ @@ -1156,4 +1157,4 @@ - \ No newline at end of file +