<?xml version="1.0" encoding='UTF-8'?>
<Rules>
    <RuleGroup id="ID0" oid="-1y2p0ij32e8cn:-1y2p0ij2wx579" class="rulegroup" name="IET XP/2003 Daily Rules - v1.1">
        <Description>TFS XP/2003 rulesets with local edits</Description>
        <Children>
            <Child refid="ID1" />
            <Child refid="ID2" />
        </Children>
    </RuleGroup>
    <RuleGroup id="ID1" oid="-1y2p0ij32e8cn:-1y2p0ij2wxp4l" class="rulegroup" name="File System">
        <Description></Description>
        <Children>
            <Child refid="ID3" />
            <Child refid="ID4" />
            <Child refid="ID5" />
            <Child refid="ID6" />
            <Child refid="ID7" />
            <Child refid="ID8" />
            <Child refid="ID9" />
        </Children>
    </RuleGroup>
    <WindowsFileRule id="ID3" oid="-1y2p0ij32e858:-1y2p0ij2wxp4k" class="rule" name="XP - Critical System Startup files">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(WINXP2003_BOOTDRIVE)</Target>
                <Severity>10000</Severity>
                <RecurseLevel>1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID11</Criteria>
            </Start>
        </StartPoints>
        <StopPoints>
            <Stop>
                <Target>$(WINXP2003_SYSTEMDRIVE)\ffastun.ffl</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMDRIVE)\ffastun.ffx</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMDRIVE)\ffastun.ff0</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMDRIVE)\temp</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMDRIVE)\ffastun.ffa</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMDRIVE)\pagefile.sys</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_PROGRAMFILES)</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMDRIVE)\hiberfil.sys</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
        </StopPoints>
    </WindowsFileRule>
    <WindowsFileRule id="ID4" oid="-1y2p0ij32e858:-1y2p0ij2wxp49" class="rule" name="XP - System32 Folder">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters>
                    <Filter>
                        <TypeId>1</TypeId>
                        <Exclude>Perflib_Perfdata*.dat</Exclude>
                        <Exclude>*log.*</Exclude>
                        <Exclude>*.log</Exclude>
                        <Exclude>*.tmp</Exclude>
                    </Filter>
                </Filters>
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\CatRoot</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\CatRoot2</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\DTCLog</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\LogFiles</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\LLS\LlsUser.LLS</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\LServer</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\NtmsData</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\NtmsData\Export</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID18</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\spool</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\wbem\Logs</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\wbem\Repository</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
        </StartPoints>
        <StopPoints>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\ShellExt</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\setup</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\dhcp</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\inetsrv\History</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\cpl.cfg</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\wins</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\ras</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\config</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\mapisvc.inf</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\inetsrv\metabase.bin</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\dllcache</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\dsa.msc</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\ffastlog.txt</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\events.txt</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\inetsrv\metabase.xml</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
        </StopPoints>
    </WindowsFileRule>
    <WindowsFileRule id="ID5" oid="-1y2p0ij32e858:-1y2p0ij2wxp3h" class="rule" name="XP - System Folder">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(WINXP2003_SYSTEMDIR)</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsFileRule>
    <WindowsFileRule id="ID6" oid="-1y2p0ij32e858:-1y2p0ij2wxp3f" class="rule" name="XP - Network Configuration Files">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\config</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\config\systemprofile</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\dhcp</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters>
                    <Filter>
                        <TypeId>1</TypeId>
                        <Exclude>*log*</Exclude>
                        <Exclude>*.chk</Exclude>
                        <Exclude>*.mdb</Exclude>
                    </Filter>
                </Filters>
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\etc\hosts</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\etc\networks</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\etc\protocol</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\etc\services</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\inetsrv\History</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\inetsrv\metabase.bin</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\ras</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\setup</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\ShellExt</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\wins</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters>
                    <Filter>
                        <TypeId>1</TypeId>
                        <Exclude>*.log</Exclude>
                        <Exclude>*edb*</Exclude>
                        <Exclude>*sdb*</Exclude>
                    </Filter>
                </Filters>
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\wins\wins_bak</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEMROOT)\security</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID17</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEMROOT)\security\templates</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID18</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\etc\lmhosts.sam</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters>
                    <Filter>
                        <TypeId>1</TypeId>
                    </Filter>
                </Filters>
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\etc\lmhosts</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters>
                    <Filter>
                        <TypeId>1</TypeId>
                    </Filter>
                </Filters>
                <Criteria>ID16</Criteria>
            </Start>
        </StartPoints>
        <StopPoints>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\dhcp\backup</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
        </StopPoints>
    </WindowsFileRule>
    <WindowsFileRule id="ID7" oid="-1y2p0ij32e858:-1y2p0ij2wxp2x" class="rule" name="XP - Critical Drivers">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEMROOT)\Driver Cache</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\smbios.dat</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID18</Criteria>
            </Start>
        </StartPoints>
        <StopPoints>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\etc\services</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\etc\networks</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\etc\hosts</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)\drivers\etc\protocol</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
        </StopPoints>
    </WindowsFileRule>
    <WindowsFileRule id="ID8" oid="-1y2p0ij32e858:-1y2p0ij2wxp2p" class="rule" name="XP - OS Support Files">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(WINXP2003_SYSTEMROOT)</Target>
                <Severity>35</Severity>
                <RecurseLevel>1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters>
                    <Filter>
                        <TypeId>1</TypeId>
                        <Exclude>*.log</Exclude>
                    </Filter>
                </Filters>
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEMROOT)\bootstat.dat</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID18</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEMROOT)\Config</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEMROOT)\inf</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEM32DIR)\dllcache</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
            <Start>
                <Target>$(WINXP2003_SYSTEMROOT)\repair</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID11</Criteria>
            </Start>
        </StartPoints>
        <StopPoints>
            <Stop>
                <Target>$(WINXP2003_SYSTEMDIR)</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\Help</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\Subscriptions</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\Web</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\Driver Cache</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEM32DIR)</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\Media</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\ShellIconCache</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\security</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\SchedLog.Txt</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\randseed.rnd</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\Cursors</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\History</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\SchedLgU.txt</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(WINXP2003_SYSTEMROOT)\temp</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
        </StopPoints>
    </WindowsFileRule>
    <WindowsFileRule id="ID9" oid="-1y2p0ij32e858:-1y2p0ij2wxp23" class="rule" name="XP - Program Files Folder">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(WINXP2003_PROGRAMFILES)</Target>
                <Severity>35</Severity>
                <RecurseLevel>1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID16</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsFileRule>
    <RuleGroup id="ID2" oid="-1y2p0ij32e8cn:-1y2p0ij2wxp1y" class="rulegroup" name="Registry">
        <Description></Description>
        <Children>
            <Child refid="ID20" />
            <Child refid="ID21" />
            <Child refid="ID22" />
            <Child refid="ID23" />
            <Child refid="ID24" />
            <Child refid="ID25" />
            <Child refid="ID26" />
            <Child refid="ID27" />
            <Child refid="ID28" />
            <Child refid="ID29" />
            <Child refid="ID30" />
            <Child refid="ID31" />
            <Child refid="ID32" />
            <Child refid="ID33" />
        </Children>
    </RuleGroup>
    <WindowsRegistryRule id="ID20" oid="-1y2p0ij32e853:-1y2p0ij2wxp1x" class="rule" name="XP - Critical Security Account Keys">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM_CCS)\\Control\\LSA</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM)\\SECURITY\\SAM\\Domains\\Account</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters>
                    <Filter>
                        <TypeId>1</TypeId>
                        <Exclude>F</Exclude>
                        <Exclude>V</Exclude>
                    </Filter>
                </Filters>
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM)\\SAM\\SAM\\Domains\\Account</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters>
                    <Filter>
                        <TypeId>1</TypeId>
                        <Exclude>F</Exclude>
                        <Exclude>V</Exclude>
                    </Filter>
                </Filters>
                <Criteria>ID35</Criteria>
            </Start>
        </StartPoints>
        <StopPoints>
            <Stop>
                <Target>$(HKLM)\\SAM\\SAM\\Domains\\Account\\Users\\000001F4</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_CCS)\\Control\\LSA\\Audit\\Sources\\twagent_sec</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM)\\SAM\\SAM\\Domains\\Account\\Users\\000001F5</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_CCS)\\Control\\LSA\\Audit\\Sources\\TripwirePrintUtility_sec</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_CCS)\\Control\\LSA\\Audit\\Sources\\TripwireAdminUtility_sec</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
        </StopPoints>
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID21" oid="-1y2p0ij32e853:-1y2p0ij2wxp1o" class="rule" name="XP - Local Admin Activity">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM)\\SAM\\SAM\\Domains\\Account\\Users\\000001F4</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID37</Criteria>
            </Start>
        </StartPoints>
        <StopPoints>
            <Stop>
                <Target>$(HKLM)\\SAM\\SAM\\Domains\\Account\\Users\\000001F4|F</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM)\\SAM\\SAM\\Domains\\Account\\Users\\000001F4|V</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
        </StopPoints>
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID22" oid="-1y2p0ij32e853:-1y2p0ij2wxp1k" class="rule" name="XP - Local Admin Login">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM)\\SAM\\SAM\\Domains\\Account\\Users\\000001F4|F</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID23" oid="-1y2p0ij32e853:-1y2p0ij2wxp1i" class="rule" name="XP - Local Admin Password Change">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM)\\SAM\\SAM\\Domains\\Account\\Users\\000001F4|V</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID24" oid="-1y2p0ij32e853:-1y2p0ij2wxp1g" class="rule" name="XP - Guest Account Activity">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM)\\SAM\\SAM\\Domains\\Account\\Users\\000001F5</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID37</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID25" oid="-1y2p0ij32e853:-1y2p0ij2wxp1e" class="rule" name="XP - Service Registry Keys">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM_Services)</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\Dhcp\\Parameters</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\LanmanServer\\Parameters</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\LicenseInfo\\FilePrint|LocalKey</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\NAVENG</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\NAVEX15</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\NTDS\\BackupInformation</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\SysmonLog\\Log Queries</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\Tcpip\\Parameters\\DNSRegisteredAdapters</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\Tcpip\\Parameters\\Interfaces</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\TMFilter|CurrentPatternName</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\TrkWks\\Parameters</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\TrkSvr\\Parameters</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\W32Time\\Parameters|msSkewPerDay</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\Wins</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
        </StartPoints>
        <StopPoints>
            <Stop>
                <Target>$(HKLM_Services)\\twagent</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\System\\twagent_sys</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\System\\TripwirePrintUtility_sys</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\Application\\twagent</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\System\\TripwireAdminUtility_sys</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\Security\\TripwireAdminUtility_sec</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\Security\\TripwirePrintUtility_sec</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\Security\\Tripwire_sec</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\Application\\Tripwire</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\Security\\twagent_sec</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\Application\\TripwirePrintUtility</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\Application\\Tripwire Agent</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
            <Stop>
                <Target>$(HKLM_EventLog)\\Application\\TripwireAdminUtility</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
        </StopPoints>
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID26" oid="-1y2p0ij32e853:-1y2p0ij2wxp0l" class="rule" name="XP - Critical System Registry Keys">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKCU_Windows_Policies)</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\Winlogon</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters>
                    <Filter>
                        <TypeId>1</TypeId>
                        <Exclude>Winlogon</Exclude>
                        <Exclude>DomainCache</Exclude>
                    </Filter>
                </Filters>
                <Criteria>ID43</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\Winlogon|DCacheUpdate</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\Winlogon\\GPExtensions</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\Drivers</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\Drivers32</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\Network</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\ProfileList</Target>
                <Severity>10000</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\WOW</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\AeDebug</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\Embedding</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\Userinstallable.drivers</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID27" oid="-1y2p0ij32e853:-1y2p0ij2wxp08" class="rule" name="XP - Software Keys">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM)\\SOFTWARE\\Clients</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM)\\SOFTWARE\\Microsoft\\Rpc</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
        </StartPoints>
        <StopPoints>
            <Stop>
                <Target>$(HKLM)\\Software\\Microsoft\\Rpc|UuidSequenceNumber</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
        </StopPoints>
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID28" oid="-1y2p0ij32e853:-1y2p0ij2wxp04" class="rule" name="XP - Hardware Keys">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM)\\hardware</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM)\\SYSTEM\\Setup</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS)\\Hardware Profiles</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID29" oid="-1y2p0ij32e853:-1y2p0ij2wxp00" class="rule" name="XP - Class Keys">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKCR)\\AllFilesystemObjects</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\AppID</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\batfile</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\CLSID</Target>
                <Severity>35</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\cmdfile</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\comfile</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Component Categories</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Directory</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Drive</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\exefile</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\file</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\FILETYPE</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Filter</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Folder</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Interface</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Typelib</Target>
                <Severity>35</Severity>
                <RecurseLevel>0</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\ldap</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\LDAPNamespace</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\lnkfile</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Media Type</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\MIME</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\NDS</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\NDSNamespace</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Network</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Pathname</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\PROTOCOLS</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\SecurityDescriptor</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Shell.Application</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Shell.Explorer</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\txtfile</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\Unknown</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\WinNT</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
            <Start>
                <Target>$(HKCR)\\WinNTNamespace</Target>
                <Severity>35</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID45</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID30" oid="-1y2p0ij32e853:-1y2p0ij2wxoz2" class="rule" name="XP - System Startup Executables">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM_WCV)\\Run</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WCV)\\RunOnce</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WCV)\\RunOnceEx</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU_WCV)\\Run</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU_WCV)\\RunOnce</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\IniFileMapping</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU)\\Control Panel\\Desktop|ScreenSaveActive</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU)\\Control Panel\\Desktop|ScreenSaverIsSecure</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU)\\Control Panel\\Desktop|ScreenSaveTimeOut</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID31" oid="-1y2p0ij32e853:-1y2p0ij2wxoys" class="rule" name="XP - Security Information Keys">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM_CCS)\\Control\\FileSystem</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS)\\Control\\NetworkProvider</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS)\\Control\\Print\\Providers\\Lanman Print Services</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS)\\Control\\SecurePipeServers</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS)\\Control\\Windows</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS_SM)\\Environment</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS_SM)\\Executive</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS_SM)\\KnownDLLs</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS_SM)\\Memory Management|ClearPageFileAtShutdown</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS_SM)\\SubSystems</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU_WCV)\\Shell Extensions</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\Image File Execution Options</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_WNTCV)\\Hotfix</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
        </StartPoints>
        <StopPoints>
            <Stop>
                <Target>$(HKLM_CCS)\\Control\\Windows|ShutdownTime</Target>
                <StopRecursion>true</StopRecursion>
            </Stop>
        </StopPoints>
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID32" oid="-1y2p0ij32e853:-1y2p0ij2wxoyd" class="rule" name="XP - Current User Registry Keys">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKCU)\\Environment</Target>
                <Severity>15</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU)\\Software\\Microsoft\\RegEdt32</Target>
                <Severity>15</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU)\\Software\\Microsoft\\SystemCertificates</Target>
                <Severity>15</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU_WCV)\\WinTrust</Target>
                <Severity>15</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU_WNTCV)\\Network\\Persistent Connections</Target>
                <Severity>15</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU_WNTCV)\\Winlogon</Target>
                <Severity>15</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKCU_WNTCV)\\Winlogon|DCacheUpdate</Target>
                <Severity>15</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID39</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsRegistryRule>
    <WindowsRegistryRule id="ID33" oid="-1y2p0ij32e853:-1y2p0ij2wxoy5" class="rule" name="XP - Critical Tripwire Registry Keys">
        <Description></Description>
        <Severity>0</Severity>
        <Actions />
        <StartPoints>
            <Start>
                <Target>$(HKLM_EventLog)\\Application\\Tripwire</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\Application\\Tripwire Agent</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\Application\\TripwireAdminUtility</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\Application\\TripwirePrintUtility</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\Application\\twagent</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\Security\\Tripwire_sec</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\Security\\TripwireAdminUtility_sec</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\Security\\TripwirePrintUtility_sec</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\Security\\twagent_sec</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\System\\TripwireAdminUtility_sys</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\System\\TripwirePrintUtility_sys</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_EventLog)\\System\\twagent_sys</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS)\\Control\\LSA\\Audit\\Sources\\TripwireAdminUtility_sec</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS)\\Control\\LSA\\Audit\\Sources\\TripwirePrintUtility_sec</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_CCS)\\Control\\LSA\\Audit\\Sources\\twagent_sec</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
            <Start>
                <Target>$(HKLM_Services)\\twagent</Target>
                <Severity>10000</Severity>
                <RecurseLevel>-1</RecurseLevel>
                <StoreContent>false</StoreContent>
                <Filters />
                <Criteria>ID35</Criteria>
            </Start>
        </StartPoints>
        <StopPoints />
    </WindowsRegistryRule>
    <RuleGroup id="ID51" oid="-1y2p0ij32e8cn:-1y2p0ij2w2psw" class="rulegroup" name="IET XP/2003 Hourly Rules - v1.1">
        <Description>IET XP/2003 Hourly rules - v1.1</Description>
        <Children />
    </RuleGroup>
    <StringVariable id="ID10" oid="-1y2p0ij32e8cg:-1y2p0ij32d94a" class="StringVariable" name="WINXP2003_BOOTDRIVE" value="C:" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID12" oid="-1y2p0ij32e8cg:-1y2p0ij32d949" class="StringVariable" name="WINXP2003_SYSTEMDRIVE" value="C:" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID13" oid="-1y2p0ij32e8cg:-1y2p0ij32d948" class="StringVariable" name="WINXP2003_PROGRAMFILES" value="C:\Program Files" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID14" oid="-1y2p0ij32e8cg:-1y2p0ij32d947" class="StringVariable" name="WINXP2003_SYSTEMROOT" value="C:\WINDOWS" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID15" oid="-1y2p0ij32e8cg:-1y2p0ij32d946" class="StringVariable" name="WINXP2003_SYSTEM32DIR" value="$(WINXP2003_SYSTEMROOT)\System32" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID19" oid="-1y2p0ij32e8cg:-1y2p0ij32d945" class="StringVariable" name="WINXP2003_SYSTEMDIR" value="$(WINXP2003_SYSTEMROOT)\System" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID34" oid="-1y2p0ij32e8cg:-1y2p0ij32d9da" class="StringVariable" name="HKLM_CCS" value="$(HKLM)\SYSTEM\CurrentControlSet" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID36" oid="-1y2p0ij32e8cg:-1y2p0ij32d9d9" class="StringVariable" name="HKLM" value="HKEY_LOCAL_MACHINE" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID38" oid="-1y2p0ij32e8cg:-1y2p0ij32d9d8" class="StringVariable" name="HKLM_Services" value="$(HKLM)\SYSTEM\CurrentControlSet\Services" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID40" oid="-1y2p0ij32e8cg:-1y2p0ij32d9d7" class="StringVariable" name="HKLM_EventLog" value="$(HKLM_Services)\Eventlog" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID41" oid="-1y2p0ij32e8cg:-1y2p0ij32d9d6" class="StringVariable" name="HKCU_Windows_Policies" value="$(HKCU)\Software\Microsoft\Windows\CurrentVersion\Policies" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID42" oid="-1y2p0ij32e8cg:-1y2p0ij32d9d5" class="StringVariable" name="HKLM_WNTCV" value="$(HKLM)\Software\Microsoft\Windows NT\CurrentVersion" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID44" oid="-1y2p0ij32e8cg:-1y2p0ij32d9d4" class="StringVariable" name="HKCR" value="HKEY_CLASSES_ROOT" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID46" oid="-1y2p0ij32e8cg:-1y2p0ij32d9d3" class="StringVariable" name="HKLM_WCV" value="$(HKLM)\Software\Microsoft\Windows\CurrentVersion" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID47" oid="-1y2p0ij32e8cg:-1y2p0ij32d9d2" class="StringVariable" name="HKCU_WCV" value="$(HKCU)\Software\Microsoft\Windows\CurrentVersion" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID48" oid="-1y2p0ij32e8cg:-1y2p0ij32d9d1" class="StringVariable" name="HKCU" value="HKEY_CURRENT_USER" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID49" oid="-1y2p0ij32e8cg:-1y2p0ij32d9d0" class="StringVariable" name="HKLM_CCS_SM" value="$(HKLM)\SYSTEM\CurrentControlSet\Control\Session Manager" Scope="0">
        <Description></Description>
    </StringVariable>
    <StringVariable id="ID50" oid="-1y2p0ij32e8cg:-1y2p0ij32d9cz" class="StringVariable" name="HKCU_WNTCV" value="$(HKCU)\Software\Microsoft\Windows NT\CurrentVersion" Scope="0">
        <Description></Description>
    </StringVariable>
    <Criteria id="ID11" oid="-1y2p0ij32e85e:-1y2p0ij32d9cy" class="Criteria" name="$(FILE_CRITICAL)" Genre="com.tripwire.si.core.fs.windows.WindowsFileSystemRule">
        <Description>TFS - RrothymcsCugdsMSnx</Description>
        <Attributes>
            <ElementType>2</ElementType>
            <Attribute>Owner</Attribute>
            <Attribute>Create</Attribute>
            <Attribute>Temp</Attribute>
            <Attribute>Read-Only</Attribute>
            <Attribute>Archive</Attribute>
            <Attribute>Stream Count</Attribute>
            <Attribute>Compressed</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>System</Attribute>
            <Attribute>Write</Attribute>
            <Attribute>Group</Attribute>
            <Attribute>DACL</Attribute>
            <Attribute>Hidden</Attribute>
            <Attribute>Offline</Attribute>
            <Attribute>Stream MD5</Attribute>
        </Attributes>
        <Attributes>
            <ElementType>1</ElementType>
            <Attribute>Owner</Attribute>
            <Attribute>Create</Attribute>
            <Attribute>Temp</Attribute>
            <Attribute>Read-Only</Attribute>
            <Attribute>Archive</Attribute>
            <Attribute>Stream Count</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>Compressed</Attribute>
            <Attribute>MD5</Attribute>
            <Attribute>SHA-1</Attribute>
            <Attribute>System</Attribute>
            <Attribute>Write</Attribute>
            <Attribute>Group</Attribute>
            <Attribute>DACL</Attribute>
            <Attribute>Size</Attribute>
            <Attribute>Hidden</Attribute>
            <Attribute>Offline</Attribute>
            <Attribute>Stream MD5</Attribute>
        </Attributes>
    </Criteria>
    <Criteria id="ID16" oid="-1y2p0ij32e85e:-1y2p0ij32d9cx" class="Criteria" name="$(FILE_STATIC)" Genre="com.tripwire.si.core.fs.windows.WindowsFileSystemRule">
        <Description>TFS - rohymcsugdsMnx</Description>
        <Attributes>
            <ElementType>2</ElementType>
            <Attribute>DACL</Attribute>
            <Attribute>Owner</Attribute>
            <Attribute>Create</Attribute>
            <Attribute>Read-Only</Attribute>
            <Attribute>Stream Count</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>Hidden</Attribute>
            <Attribute>Offline</Attribute>
            <Attribute>System</Attribute>
            <Attribute>Write</Attribute>
            <Attribute>Stream MD5</Attribute>
            <Attribute>Group</Attribute>
        </Attributes>
        <Attributes>
            <ElementType>1</ElementType>
            <Attribute>Owner</Attribute>
            <Attribute>Create</Attribute>
            <Attribute>Read-Only</Attribute>
            <Attribute>Stream Count</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>MD5</Attribute>
            <Attribute>System</Attribute>
            <Attribute>Write</Attribute>
            <Attribute>Group</Attribute>
            <Attribute>DACL</Attribute>
            <Attribute>Size</Attribute>
            <Attribute>Hidden</Attribute>
            <Attribute>Offline</Attribute>
            <Attribute>Stream MD5</Attribute>
        </Attributes>
    </Criteria>
    <Criteria id="ID17" oid="-1y2p0ij32e85e:-1y2p0ij32d9cw" class="Criteria" name="$(FILE_DYNAMIC)" Genre="com.tripwire.si.core.fs.windows.WindowsFileSystemRule">
        <Description>TFS - rothycugds</Description>
        <Attributes>
            <ElementType>2</ElementType>
            <Attribute>DACL</Attribute>
            <Attribute>Owner</Attribute>
            <Attribute>Create</Attribute>
            <Attribute>Read-Only</Attribute>
            <Attribute>Temp</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>Hidden</Attribute>
            <Attribute>Offline</Attribute>
            <Attribute>System</Attribute>
            <Attribute>Group</Attribute>
        </Attributes>
        <Attributes>
            <ElementType>1</ElementType>
            <Attribute>DACL</Attribute>
            <Attribute>Owner</Attribute>
            <Attribute>Create</Attribute>
            <Attribute>Read-Only</Attribute>
            <Attribute>Temp</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>Hidden</Attribute>
            <Attribute>Offline</Attribute>
            <Attribute>System</Attribute>
            <Attribute>Group</Attribute>
        </Attributes>
    </Criteria>
    <Criteria id="ID18" oid="-1y2p0ij32e85e:-1y2p0ij32d9cv" class="Criteria" name="$(FILE_STATIC) -&amp;write" Genre="com.tripwire.si.core.fs.windows.WindowsFileSystemRule">
        <Description>TFS - rohycsugdsMnx</Description>
        <Attributes>
            <ElementType>2</ElementType>
            <Attribute>DACL</Attribute>
            <Attribute>Owner</Attribute>
            <Attribute>Create</Attribute>
            <Attribute>Read-Only</Attribute>
            <Attribute>Stream Count</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>Hidden</Attribute>
            <Attribute>Offline</Attribute>
            <Attribute>System</Attribute>
            <Attribute>Stream MD5</Attribute>
            <Attribute>Group</Attribute>
        </Attributes>
        <Attributes>
            <ElementType>1</ElementType>
            <Attribute>Owner</Attribute>
            <Attribute>Create</Attribute>
            <Attribute>Read-Only</Attribute>
            <Attribute>Stream Count</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>MD5</Attribute>
            <Attribute>System</Attribute>
            <Attribute>Group</Attribute>
            <Attribute>DACL</Attribute>
            <Attribute>Size</Attribute>
            <Attribute>Hidden</Attribute>
            <Attribute>Offline</Attribute>
            <Attribute>Stream MD5</Attribute>
        </Attributes>
    </Criteria>
    <Criteria id="ID35" oid="-1y2p0ij32e85e:-1y2p0ij32d9cu" class="Criteria" name="$(REG_STATIC)" Genre="com.tripwire.si.core.fs.registry.WindowsRegistryRule">
        <Description>TFS - ugdsTM</Description>
        <Attributes>
            <ElementType>2</ElementType>
            <Attribute>DACL</Attribute>
            <Attribute>Owner</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>Group</Attribute>
        </Attributes>
        <Attributes>
            <ElementType>1</ElementType>
            <Attribute>Data Type</Attribute>
            <Attribute>MD5</Attribute>
        </Attributes>
    </Criteria>
    <Criteria id="ID37" oid="-1y2p0ij32e85e:-1y2p0ij32d9ct" class="Criteria" name="$(REG_STATIC) +&amp;write" Genre="com.tripwire.si.core.fs.registry.WindowsRegistryRule">
        <Description>TFS - ugdsmTM</Description>
        <Attributes>
            <ElementType>2</ElementType>
            <Attribute>DACL</Attribute>
            <Attribute>Owner</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>Write</Attribute>
            <Attribute>Group</Attribute>
        </Attributes>
        <Attributes>
            <ElementType>1</ElementType>
            <Attribute>Data Type</Attribute>
            <Attribute>MD5</Attribute>
        </Attributes>
    </Criteria>
    <Criteria id="ID39" oid="-1y2p0ij32e85e:-1y2p0ij32d9cs" class="Criteria" name="$(REG_DYNAMIC)" Genre="com.tripwire.si.core.fs.registry.WindowsRegistryRule">
        <Description>TFS - ugdsT</Description>
        <Attributes>
            <ElementType>2</ElementType>
            <Attribute>DACL</Attribute>
            <Attribute>Owner</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>Group</Attribute>
        </Attributes>
        <Attributes>
            <ElementType>1</ElementType>
            <Attribute>Data Type</Attribute>
        </Attributes>
    </Criteria>
    <Criteria id="ID43" oid="-1y2p0ij32e85e:-1y2p0ij32d9cr" class="Criteria" name="$(REG_CRITICAL)" Genre="com.tripwire.si.core.fs.registry.WindowsRegistryRule">
        <Description>TFS - ugdsmTMS</Description>
        <Attributes>
            <ElementType>2</ElementType>
            <Attribute>DACL</Attribute>
            <Attribute>Owner</Attribute>
            <Attribute>SACL</Attribute>
            <Attribute>Write</Attribute>
            <Attribute>Group</Attribute>
        </Attributes>
        <Attributes>
            <ElementType>1</ElementType>
            <Attribute>Data Type</Attribute>
            <Attribute>SHA-1</Attribute>
            <Attribute>MD5</Attribute>
        </Attributes>
    </Criteria>
    <Criteria id="ID45" oid="-1y2p0ij32e85e:-1y2p0ij32d9cq" class="Criteria" name="$(REG_CLASS)" Genre="com.tripwire.si.core.fs.registry.WindowsRegistryRule">
        <Description>TFS - ugdT</Description>
        <Attributes>
            <ElementType>2</ElementType>
            <Attribute>DACL</Attribute>
            <Attribute>Owner</Attribute>
            <Attribute>Group</Attribute>
        </Attributes>
        <Attributes>
            <ElementType>1</ElementType>
            <Attribute>Data Type</Attribute>
        </Attributes>
    </Criteria>
</Rules>