filter_main_startmenu: ParentImage:
'C:\Windows\System32\control.exe' CommandLine|startswith:
'"C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL "C:\Windows\System32\' CommandLine|endswith:
'.cpl",' condition:selection and not 1 of filter_main_* Falsepositives:
-False positives depend on scripts and administrative tools used in the monitored environment Level:medium