Microsoft AppLocker

Microsoft introduced AppLocker with Windows 7 and Server 2008 R2. AppLocker allows you to specify which users or groups can run particular applications in your organization based on unique identities of files. If you use AppLocker, you can Whitelist or Blacklist applications by creating rules to allow or deny applications from running.

It is highly recommended that you use a whitelisting approach over blacklisting. Blacklisting works by allowing all applications to run by default, except for a list of applications that should be denied, the blacklist. It is a simple task to bypass blacklisting restrictions by changing some fundamental aspects of an application, effectively bypassing the security control. Whitelisting, ...

Get Industrial Cybersecurity now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.