Image:\\reg.exe (CommandLine:SOFTWARE\\Microsoft\\Windows\ Defender\\Exclusions\\Paths* OR CommandLine:SOFTWARE\\Microsoft\\Microsoft\ Antimalware\\Exclusions\\Paths*) (CommandLine:ADD\ * CommandLine:\/t\ * CommandLine:REG_DWORD\ * CommandLine:\/v\ * CommandLine:\/d\ * CommandLine:0*)