AppLocker & WDAC

2. Executable Rules

Executable rules use file hashes to identify allowed programs. These are useful for enforcing strict control over known, trusted applications.
Use case: Allowing only a specific version of a critical tool (e.g., notepad.exe from C:\Windows\System32).
Example command:

New-AppLockerRule -Hash "a1b2c3d4e5f67890" -Action Allow

3. File Rules

File rules restrict or allow execution based on file paths. These are ideal for controlling access to specific directories or preventing execution from unauthorized locations.
Use case: Blocking all executable files in a user’s personal folder (e.g., C:\Users\*\Downloads\*) to prevent unintended software runs.
Example command:

New-AppLockerRule -Path "C:\Users\*\Downloads\*" -Action Deny

4. Publisher Rules

Publisher rules enforce application control based on digital signatures. These are critical for trusting software from specific vendors while blocking unsigned or untrusted sources.
Use case: Allowing only applications signed by a known publisher (e.g., Microsoft) while denying unsigned third-party tools.
Example command:

New-AppLockerRule -Publisher "Microsoft Corporation" -Action Allow