SEC 440 AppLocker Lab - JadenGil/Jaden-Tech-Journal GitHub Wiki

Installation:

Open Group Policy Management and make a new organizational unit called AppLocker:

image

Then make a GPO in that OU called AppLocker:

image

Then we edit the new GPO by going to “Computer Configuration” > Policies > Windows Settings > Security Settings > Application Control Policies > Applocker

Then right-click on Executable Rules then create default rules

It should look like this:

image

Then right click where the rules are and select "Create New Rule" and when we get to permissions select "deny"

image

Then under conditions select "Publisher"

image

Select Putty for this example:

image

As an exception to this rule I'll be using google chrome (I don't have internet explorer)

image

The exceptions page should look like this:

image

Deliverable 1:

image

Now we want to enter "Configure Rule Enforcement":

image

Now make sure the first configured box is checked and close GPO editor

image


Part 2

For part 2 we will want to open "Services" and we want to start application identity:

image