Added AppLocker log source
This commit is contained in:
@@ -74,3 +74,12 @@ logsources:
|
||||
service: windefend
|
||||
conditions:
|
||||
LogName: 'Microsoft-Windows-Windows Defender/Operational'
|
||||
windows-applocker:
|
||||
product: windows
|
||||
service: applocker
|
||||
conditions:
|
||||
LogName:
|
||||
- 'Microsoft-Windows-AppLocker/MSI and Script'
|
||||
- 'Microsoft-Windows-AppLocker/EXE and DLL'
|
||||
- 'Microsoft-Windows-AppLocker/Packaged app-Deployment'
|
||||
- 'Microsoft-Windows-AppLocker/Packaged app-Execution'
|
||||
|
||||
Reference in New Issue
Block a user