AppLocker was introduced in Windows Server 2008 R2 and Windows 7, and advances the application control functionality of Software Restriction Policies. AppLocker contains new capabilities and extensions that allow you to create rules to allow or deny applications from running based on unique identities of files. It also allows you to specify which users or groups can run those applications. By enabling AppLocker Windows event logging it allows you to alert on those times when the AppLocker service is generating warnings or errors, which could be indicative of an attacker accessing a restricted file or resource. For example, AppLocker allows an administrator to add executable files to an allowed list so the logging of an unknown .exe or .dll file attempting to execute may prove to be valuable for detection purposes.
Number of occurrences in rules | Eventid | Event log | Event source or category |
|---|---|---|---|
1 | 8003 | Microsoft-WindowsAppLocker/EXE and DLL | Microsoft-Windows-AppLocker |
1 | 8004 | Microsoft-WindowsAppLocker/EXE and DLL | Microsoft-Windows-AppLocker |
1 | 8005 | Microsoft-WindowsAppLocker/MSI and Script | Microsoft-Windows-AppLocker |
1 | 8006 | Microsoft-WindowsAppLocker/MSI and Script | Microsoft-Windows-AppLocker |