Windows Application Whitelisting

Application whitelisting events should be collected to look for applications that have been blocked from execution. Any blocked applications could be malware or users trying to run unapproved software. Software Restriction Policies (SRP) is supported on Windows XP and above. The AppLocker feature is available for Windows 7 and above Enterprise and Ultimate editions only. Application Whitelisting events can be collected if SRP or AppLocker are actively being used on the network.
AIS Managed SIEM

SIEM Events

Application Ran

Application Ran

Application Installed

Application Installed

SRP Block

SRP Block

Last modified September 14, 2021