TargetObject|endswith:
'\Microsoft\Windows\CurrentVersion\Run\aurora-dashboard' Details:
'C:\Program Files\Aurora-Agent\tools\aurora-dashboard.exe' filter_everything: TargetObject|endswith:
'\Microsoft\Windows\CurrentVersion\Run\Everything' Details|endswith:
'\Everything\Everything.exe" -startup' condition:all of current_version_* and not 1 of filter_* Falsepositives:
-Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
-Legitimate administrator sets up autorun keys for legitimate reason Level:medium