Skip to content

Commit c902dbf

Browse files
committed
Add application_execution tag to certain Amcache entries
1 parent 1c5ec4d commit c902dbf

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

data/tag_windows.txt

+1
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ application_execution
1111
data_type is 'windows:registry:mrulistex' AND entries contains '.exe'
1212
data_type is 'windows:registry:userassist' AND value_name contains '.exe'
1313
data_type is 'windows:tasks:job'
14+
parser is 'winreg/amcache' AND data_type is 'windows:registry:key_value' AND values contains 'BundleManifestPath'
1415

1516
# Tags Windows application installation events.
1617
application_install

0 commit comments

Comments
 (0)