Query Details
Tags: Query: DeviceRegistryEvents | where ActionType == @"RegistryValueSet" | where RegistryKey == @"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\TemporaryPaths" References:
The query is looking for events in the Device Registry where the ActionType is "RegistryValueSet" and the RegistryKey is "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\TemporaryPaths".

Ali Hussein
Released: September 14, 2023
Tables
Keywords
Operators