Unleashing the Power of AppLocker: How to Get Started and Go Beyond the Basics

Date: February 12, 2020

Join Senior Security Consultant and Microsoft MVP Oddvar Moe in a two-part webinar series as he walks through how to get started with AppLocker, go beyond the standard setup, and effectively harden the Windows client configuration. The webinar will detail useful information about the effective security measure and include live demonstrations.

Part 1 – Recorded on January 29, 2020

Deck including links can be found here.

Part 2 – Recorded on February 12, 2020

Deck including links can be found here.

Why AppLocker?

Application whitelisting is one of the most powerful ways to stop a variety of attacks and, when configured correctly, will significantly increase the amount of time an attacker will need to spend to get around it. Additionally, application whitelisting is effective against automated attacks, such as ransomware.

What will be covered in the series?

In the first webinar (on January 29), Oddvar will cover how to get started with AppLocker and what you need to know in order to build an effective AppLocker policy in your organization. The basic components of the policy, the pre-requisites for implementation, and a how-to on piloting AppLocker will be discussed and demonstrated. You will learn how to deploy a ruleset in audit mode and gather logs centrally to see the effects prior to putting it into production. Lastly, Oddvar will provide instruction on how to enable the ruleset and maintain it over time.

During the second installment (on February 12), Oddvar will delve more deeply into how to identify weaknesses in your AppLocker configuration. You will gain a better understanding of what to look for and what tools are available to make your AppLocker configuration as strong as possible. Oddvar will demonstrate how to use AaronLocker to automate rule building and will reveal his own custom written PowerAL module that was developed to discover weaknesses in the configuration.