((EventID:5007 NewValue:\\Windows\ Defender\\Windows\ Defender\ Exploit\ Guard\\Controlled\ Folder\ Access\\AllowedApplications\\*) (NewValue:\\Users\\Public\\* OR NewValue:\\AppData\\Local\\Temp\\* OR NewValue:\\Desktop\\* OR NewValue:\\PerfLogs\\* OR NewValue:\\Windows\\Temp\\*)) OR (EventID:5007 OldValue:\\Windows\ Defender\\Windows\ Defender\ Exploit\ Guard\\Controlled\ Folder\ Access\\ProtectedFolders\\*)