Getting Started With AppLocker
ID: 6673b1c2-882f-5bc5-9d3d-c286d20a67c8
STIX ID: report--6673b1c2-882f-5bc5-9d3d-c286d20a67c8
Feed Name: Black Hills Infosec Blog
Threat Score
This blog post demonstrates how an attacker can weaponize a simple backdoor (using the ADHD toolkit to deliver a Meterpreter payload) on a default Windows 10 system, and then walks through configuring Windows AppLocker (creating default rules, starting the Application Identity service, and testing with a standard user) to implement directory-based application whitelisting that can block the majority of drive-by attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
