logo

Getting Started With AppLocker

ID: 6673b1c2-882f-5bc5-9d3d-c286d20a67c8

STIX ID: report--6673b1c2-882f-5bc5-9d3d-c286d20a67c8

Feed Name: Black Hills Infosec Blog

Threat Score
30/100

Date Published: 2019-09-30

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post demonstrates how an attacker can weaponize a simple backdoor (using the ADHD toolkit to deliver a Meterpreter payload) on a default Windows 10 system, and then walks through configuring Windows AppLocker (creating default rules, starting the Application Identity service, and testing with a standard user) to implement directory-based application whitelisting that can block the majority of drive-by attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.