Windows Application Whitelisting
Application whitelisting events should be collected to look for applications that have been blocked from execution. Any blocked applications could be malware or users trying to run unapproved software. Software Restriction Policies (SRP) is supported on Windows XP and above. The AppLocker feature is available for Windows 7 and above Enterprise and Ultimate editions only. Application Whitelisting events can be collected if SRP or AppLocker are actively being used on the network.
Related Solution
AIS Managed SIEM
SIEM Events
Application Ran
Application Ran
Application Installed
Application Installed
SRP Block
SRP Block
Last modified
September 14, 2021