Files
splunk-security_content/lookups/prohibited_apps_launching_cmd.csv
pyth0n1c 29b2332652 more cleanup of lookups to follow new format.
this involved renaming some CSVs to remove the
dates from them or force their naming schema to
match the corresponding YML name for CSV
detections
2025-01-03 10:27:49 -08:00

19 lines
416 B
CSV

prohibited_applications,isProhibited
winword.exe,prohibited
EXCEL.EXE,prohibited
OUTLOOK.EXE,prohibited
POWERPNT.EXE,prohibited
visio.exe,prohibited
mspub.exe,prohibited
Acrobat.exe,prohibited
Acrord32.exe,prohibited
chrome.exe,prohibited
iexplore.exe,prohibited
opera.exe,prohibited
firefox.exe,prohibited
java.exe,prohibited
powershell.exe,prohibited
mshta.exe, prohibited
zoom.exe,prohibitied
node.exe,prohibited