name: is_windows_system_file id: ce238622-4d8f-41a4-a747-5d0adab9c854 version: 4 creation_date: '2019-10-16' modification_date: '2026-05-13' author: Splunk Threat Research Team lookup_type: csv description: A full baseline of executable files in Windows\System32 and Windows\Syswow64, including sub-directories from Server 2016 and Windows 10. min_matches: 1 case_sensitive_match: false