Skip to content

Conversation

@swachchhanda000
Copy link
Member

No description provided.

@phantinuss phantinuss requested a review from Copilot January 12, 2026 12:42
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds registry monitoring rules for Hypervisor-protected Code Integrity (HVCI) and Vulnerable Driver Blocklist security features to detect tampering attempts.

Changes:

  • Added HVCI registry path monitoring to detect when this security feature is disabled
  • Added Vulnerable Driver Blocklist registry monitoring
  • Applied changes to both standard and block configuration files

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.

File Description
sysmonconfig-export.xml Added HVCI tamper detection and Vulnerable Driver Blocklist monitoring rules
sysmonconfig-export-block.xml Added HVCI and Vulnerable Driver Blocklist registry monitoring rules

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@swachchhanda000 swachchhanda000 changed the title new: add hvci and vulerabledriverblockenable registry new: add hvci and vulnerabledriverblockenable registry Jan 12, 2026
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@swachchhanda000 swachchhanda000 merged commit 5ba379c into master Jan 12, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants