更新日志
- 新增遥测组别
Telemetry
,默认状态为关闭 - 新增以下规则组:
Suspicious.AppCertDLLs
Suspicious.AppInitDLLs
Suspicious.NetDebugger
Suspicious.NetWinAppXRT
Telemetry.ActiveSetup
Telemetry.CredentialProviders
Telemetry.LSAConfig
Telemetry.PowerShell
Telemetry.ReadBrowserData
Telemetry.TerminalServer
- 其他规则组调整
What's Changed
- Added new group category
Telemetry
, the default state is off - The following rule groups have been added:
Suspicious.AppCertDLLs
Suspicious.AppInitDLLs
Suspicious.NetDebugger
Suspicious.NetWinAppXRT
Telemetry.ActiveSetup
Telemetry.CredentialProviders
Telemetry.LSAConfig
Telemetry.PowerShell
Telemetry.ReadBrowserData
Telemetry.TerminalServer
- Other ruleset adjustments
Full Changelog: v0.1.6...v0.1.7