Jump to content

Recommended Posts

Posted

I've switched to Applocker for our W10 installs and replicated the Block and Whitelist setup we used to have with SRP.

 

However I'm curious to know what anyone else has done with this. We've got the Default rules enabled, one of which is to Allow Everyone to run executables in the Windows folder. If you don't have this they can't login, but if you do have this you can run any executable (bcdedit.exe etc) in the Windows folder by creating hyperlinks in Word etc. Thats not exactly what I'd like!

 

Whitelisting everything needed in the Windows folder would be a nightmare - so how do you deal with this?

Posted
There's still the standard Admin/user security system, they're not going to have rights to edit bcd etc. Same as any system without SRP/Applocker
Posted
Yeah they still have to authenticate to commit any changes, but without checking every executable in the %WINDIR% folder (and subfolders) I wasn't sure whether they will all require elevation!
Posted
Can't you just put an exception into the default allow Windows allow rule ? e.g. exception path - C:\Windows\notepad.exe - this should disable notepad shouldn't it?
Posted
Can't you just put an exception into the default allow Windows allow rule ? e.g. exception path - C:\Windows\notepad.exe - this should disable notepad shouldn't it?

 

Yes, that's exactly what I have done (for the likes of regedit) but I was curious to know if other people were doing the same sort of thing . I.e If you use the default whitelist rule for %WINDIR% what do you then block (or add an exception)?

Posted
I don't really get the problem, if standard users could run something they could do it before you switched, and anything that compromises security requires admin.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...