new: AppLocker Audit Mode - Application or Script Would Have Been Blo…#1007
new: AppLocker Audit Mode - Application or Script Would Have Been Blo…#1007heyyanu wants to merge 1 commit intoYamato-Security:mainfrom
Conversation
|
@heyyanu Thanks for creating a rule for this! I noticed that there is a rule in the upstream sigma repository for blocking and this rule seems very similar so what about submitting to the upstream sigma repo? |
|
@YamatoSecurity The rule has been added to the sigma folder. |
|
@heyyanu So this repository is only for adding rules to the |
|
@YamatoSecurity Thank you for the detailed explanation! |
…cked - closes #767
Summary
Adds a new detection rule for AppLocker audit mode events where applications,
scripts or DLLs would have been blocked if AppLocker was enforced.
Covers Event IDs:
Related Issue
Closes #767
MITRE ATT&CK