INNER CODE UNIT · Python
path
magicsword-io/LOLRMM · bin/detection_paths.py:19
path = path[1:-1]
path = path.replace("/", "\\")
directory = ntpath.dirname(path)
_, location = ntpath.splitdrive(directory)
# A drive letter, root separator or wildcard is not installation context.
# Unexpanded variables/placeholders would not match raw process telemetry.
if not re.search(r"[a-zA-Z0-9]", location) or any(c in path for c in "%<>"):
return None
components = {
part.casefold() for part in location.split("\\")
if re.search(r"[a-zA-Z0-9]", part)
}
if components <= {"windows", "system32", "syswow64", "sysnative"}:
return None
# Anchor relative directory suffixes; preserve explicit wildcard roots.
if not ntpath.isabs(path) and not path.startswith("*"):
path = "\\" + path