diff --git a/sysmon.xml b/sysmon.xml
index 1629ffc..49185be 100644
--- a/sysmon.xml
+++ b/sysmon.xml
@@ -282,7 +282,7 @@
C:\Users
C:\Recycle
C:\ProgramData
- C:\Windows\Temp
+ C:\Windows\
\
C:\perflogs
C:\intel
@@ -378,6 +378,7 @@
C:\ProgramData\Microsoft\Windows Defender\Platform\
+ C:\Windows\system32\svchost.exe
AppData\Local\Microsoft\Teams\current\Teams.exe
.microsoft.com
microsoft.com.akadns.net
@@ -423,7 +424,34 @@
-
+ samlib.dll
+ advapi32.dll
+ crypt32.dll
+ cryptdll.dll
+ gdi32.dll
+ imm32.dll
+ msasn1.dll
+ msvcrt.dll
+ rpcrt4.dll
+ rsaenh.dll
+ samlib.dll
+ sechost.dll
+ secur32.dll
+ shell32.dll
+ shlwapi.dll
+ sspicli.dll
+ user32.dll
+ vaultcli.dll
+ dbghelp.dll
+ winhttp.dll
+ credui.dll
+
+ dnsapi.dll
+ rtutils.dll
+ urlmon.dll
+ sensapi.dll
+ rasapi32.dll
+ napinsp.dll
@@ -585,7 +613,6 @@
.crx
.dmp
.docm
- .otm
.dll
.exe
.exe.log