LoFP LoFP / unlikely but if you experience fps add specific processes and locations you would like to monitor for

Techniques

Sample rules

Potential Persistence Via MyComputer Registry Keys

Description

Detects modification to the “Default” value of the “MyComputer” key and subkeys to point to a custom binary that will be launched whenever the associated action is executed (see reference section for example)

Detection logic

condition: selection
selection:
  TargetObject|contains: \Microsoft\Windows\CurrentVersion\Explorer\MyComputer
  TargetObject|endswith: (Default)