Skip to content

Commit 85b88ac

Browse files
Merge pull request SwiftOnSecurity#98 from bartblaze/patch-1
Add scripting filename targets
2 parents 89bb099 + 9fb44e9 commit 85b88ac

1 file changed

Lines changed: 7 additions & 1 deletion

File tree

sysmonconfig-export.xml

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -486,10 +486,13 @@
486486
<TargetFilename condition="end with">.job</TargetFilename> <!--Scheduled task-->
487487
<TargetFilename condition="end with">.pptm</TargetFilename> <!--Microsoft:Office:Word: Macro-->
488488
<TargetFilename condition="end with">.ps1</TargetFilename> <!--PowerShell [ More information: http://www.hexacorn.com/blog/2014/08/27/beyond-good-ol-run-key-part-16/ ] -->
489+
<TargetFilename condition="end with">.sct</TargetFilename> <!--Scripting | Credit @bartblaze -->
489490
<TargetFilename condition="end with">.sys</TargetFilename> <!--System driver files-->
490491
<TargetFilename condition="end with">.scr</TargetFilename> <!--System driver files-->
491492
<TargetFilename condition="end with">.vbe</TargetFilename> <!--VisualBasicScripting-->
492493
<TargetFilename condition="end with">.vbs</TargetFilename> <!--VisualBasicScripting-->
494+
<TargetFilename condition="end with">.wsc</TargetFilename> <!--Scripting | Credit @bartblaze -->
495+
<TargetFilename condition="end with">.wsf</TargetFilename> <!--Scripting | Credit @bartblaze -->
493496
<TargetFilename condition="end with">.xlsm</TargetFilename> <!--Microsoft:Office:Word: Macro-->
494497
<TargetFilename condition="end with">.ocx</TargetFilename> <!--Microsoft:ActiveX-->
495498
<TargetFilename condition="end with">proj</TargetFilename><!--Microsoft:MSBuild:Script: [ https://twitter.com/subTee/status/885919612969394177 ] -->
@@ -791,15 +794,18 @@
791794
<TargetFilename condition="end with">.cmd</TargetFilename> <!--Batch scripting | Credit @ion-storm -->
792795
<TargetFilename condition="end with">.doc</TargetFilename> <!--Office doc potentially with macro -->
793796
<TargetFilename condition="end with">.hta</TargetFilename> <!--Scripting-->
797+
<TargetFilename condition="end with">.jse</TargetFilename> <!--Registry File-->
794798
<TargetFilename condition="end with">.lnk</TargetFilename> <!--Shortcut file | Credit @ion-storm -->
795799
<TargetFilename condition="end with">.ppt</TargetFilename> <!--Office doc potentially with macros-->
796800
<TargetFilename condition="end with">.ps1</TargetFilename> <!--PowerShell-->
797801
<TargetFilename condition="end with">.ps2</TargetFilename> <!--PowerShell-->
798802
<TargetFilename condition="end with">.reg</TargetFilename> <!--Registry File-->
799-
<TargetFilename condition="end with">.jse</TargetFilename> <!--Registry File-->
803+
<TargetFilename condition="end with">.sct</TargetFilename> <!--Scripting | Credit @bartblaze -->
800804
<TargetFilename condition="end with">.vb</TargetFilename> <!--VisualBasicScripting files-->
801805
<TargetFilename condition="end with">.vbe</TargetFilename> <!--VisualBasicScripting files-->
802806
<TargetFilename condition="end with">.vbs</TargetFilename> <!--VisualBasicScripting files-->
807+
<TargetFilename condition="end with">.wsc</TargetFilename> <!--Scripting | Credit @bartblaze -->
808+
<TargetFilename condition="end with">.wsf</TargetFilename> <!--Scripting | Credit @bartblaze -->
803809
</FileCreateStreamHash>
804810

805811
<RuleGroup name="" groupRelation="or">

0 commit comments

Comments
 (0)