Commit e78e763
committed
63: New virtualuzation, service, firewall, filetype monitoring
- Now monitoring VirtualStore UAC compatibility virtualization file writes, which may be used as a persistence cloaking mechanism
- New monitoring of "ServiceManifest" key for services, persistence mechanism I found
- New domain-specific firewall monitoring
- New monitoring of "Show hidden files" and "Show file extensions" and "Show system files" settings, which malware sometimes disables to frustrate novice users
- Added vbe file monitoring, more filetypes coming soon as they are tested
- New Win10 1709 services exclusions
- More comments! Everybody loves comments
- Rearranged various areas1 parent 1c19d2b commit e78e763
1 file changed
Lines changed: 69 additions & 58 deletions
0 commit comments