Skip to content

Commit

Permalink
Add application_execution tag to certain Amcache entries
Browse files Browse the repository at this point in the history
  • Loading branch information
pyllyukko committed May 6, 2022
1 parent 1c5ec4d commit c902dbf
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions data/tag_windows.txt
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ application_execution
data_type is 'windows:registry:mrulistex' AND entries contains '.exe'
data_type is 'windows:registry:userassist' AND value_name contains '.exe'
data_type is 'windows:tasks:job'
parser is 'winreg/amcache' AND data_type is 'windows:registry:key_value' AND values contains 'BundleManifestPath'

# Tags Windows application installation events.
application_install
Expand Down

0 comments on commit c902dbf

Please sign in to comment.