Changeset 493
- Timestamp:
- 06/06/07 18:57:15 (1 year ago)
- Files:
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
honeyclient/branches/exp/mbriggs-db/etc/honeyclient.xml
r491 r493 157 157 <regex>C:/WINDOWS/SoftwareDistribution/ReportingEvents.log</regex> 158 158 <regex>C:/WINDOWS/SoftwareDistribution/WuRedir.*</regex> 159 <regex>C:/WINDOWS/SYSTEM32</regex> 159 160 <regex>C:/WINDOWS/SYSTEM32/config/SecEvent.evt</regex> 160 161 <regex>C:/WINDOWS/SYSTEM32/config/SysEvent.evt</regex> … … 163 164 <regex>C:/WINDOWS/SYSTEM32/config/system.LOG</regex> 164 165 <regex>C:/WINDOWS/SYSTEM32/Macromed/Flash.*</regex> 166 <regex>C:/WINDOWS/SYSTEM32/perfc009.dat</regex> 167 <regex>C:/WINDOWS/SYSTEM32/perfd009.dat</regex> 168 <regex>C:/WINDOWS/SYSTEM32/perfh009.dat</regex> 169 <regex>C:/WINDOWS/SYSTEM32/perfi009.dat</regex> 170 <regex>C:/WINDOWS/SYSTEM32/PerfStringBackup.INI</regex> 165 171 <regex>C:/WINDOWS/SYSTEM32/wbem.*</regex> 166 172 <regex>C:/WINDOWS/WindowsUpdate.log</regex> … … 214 220 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Macromedia\\FlashPlayer$</regex> 215 221 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\RNG$</regex> 222 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\PCHealth\\PchSvc$</regex> 223 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\.*$</regex> 224 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM.*$</regex> 216 225 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\BITS$</regex> 217 226 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Group Policy\\State\\Machine\\Extension-List\\.*$</regex> … … 219 228 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\.*$</regex> 220 229 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Auto Update.*$</regex> 221 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\.*$</regex>222 230 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Prefetcher$</regex> 223 231 <regex>^HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Notify\\WgaLogon\\Settings$</regex>
