T1679
Selective Exclusion
Windowsnothing on this site yetT1679 on attack.mitre.org
Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution. Some file extensions that adversaries may avoid encrypting include `.dll`, `.exe`, and `.lnk`.
how MITRE says to see it
Detection of Selective Exclusion
- A process with no prior history or outside of known whitelisted tools initiates file or registry modifications to configure exclusion rules for antivirus, backup, or file-handling systems.