05-12-2022 07:25 AM
We created a bioc using a reg key
Seems to work
preset = xdr_registry| filter (action_registry_key_name contains "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\USBSTOR\Enum" and event_sub_type = REGISTRY_CREATE_KEY)