diff --git a/EDR Investigative Queries/File creations in non C directory.md b/EDR Investigative Queries/File creations in non C directory.md index cce67eb..46b36fb 100644 --- a/EDR Investigative Queries/File creations in non C directory.md +++ b/EDR Investigative Queries/File creations in non C directory.md @@ -1,7 +1,6 @@ # File creations in non C:\ directory - ## EDR CDM [Cloud Console queries] ``` Event Type Id:8003-File Activity AND Disposition:1 AND NOT File Path Token:c:\ AND Device OS Type:100-Windows -``` \ No newline at end of file +```