Skip to content

Instantly share code, notes, and snippets.

@olafhartong
Created August 16, 2022 17:19
Show Gist options
  • Save olafhartong/30ed8b22e77c21bb04af14038a47b1a5 to your computer and use it in GitHub Desktop.
Save olafhartong/30ed8b22e77c21bb04af14038a47b1a5 to your computer and use it in GitHub Desktop.
<Sysmon schemaversion="4.82">
<EventFiltering>
<RuleGroup name="" groupRelation="or">
<FileBlockExecutable onmatch="include">
<TargetFilename condition="contains all">C:\Users;Downloads</TargetFilename>
</FileBlockExecutable>
</RuleGroup>
</EventFiltering>
</Sysmon>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment