Files
splunk-security_content/lookups/csv/is_windows_system_file.yml

11 lines
387 B
YAML

name: is_windows_system_file
id: ce238622-4d8f-41a4-a747-5d0adab9c854
version: 4
creation_date: '2019-10-16'
modification_date: '2026-05-13'
author: Splunk Threat Research Team
lookup_type: csv
description: A full baseline of executable files in Windows\System32 and Windows\Syswow64, including sub-directories from Server 2016 and Windows 10.
min_matches: 1
case_sensitive_match: false