Open atc0005 opened 1 year ago
Some additional thoughts that came to me earlier:
PendingFileRenameOperations
registry key valueMULTI_SZ
registry key value types
spool
firefox
chrome
It's probably worth adding explicit entries to ignore
spool
paths for the time being.
It doesn't look like this support is available yet. There is support for ignoring paths, but not specific values in a given registry key.
Overview
Recently we've seen a spread of alerts related to pending file rename operations associated with printer drivers, all of which have been determined to not require a system reboot.
Example:
All told, I've seen these two paths referenced thus far:
C:\Windows\system32\spool\DRIVERS\x64
C:\Windows\system32\spool\V4Dirs
It's probably worth adding explicit entries to ignore
spool
paths for the time being.References