Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
ADD : %windir% in CAR-2021-05-012.yaml (#150)
I used this rule with the EventID 4697 and had cases where the service file path was starting with "%windir%\" which equals to "C:\Windows\" if Windows is installed on C:. I didn't check if EventID 7045 translates "%windir%" to "C:\Windows", but I don't think so as %systemroot% is not translated in the event.
- Loading branch information