Forum Discussion
Livi_1
Nov 06, 2022Copper Contributor
Microsoft recommended block rules for DLLs
Has anyone has experience working with the DLL rules. Currently we have implemented Microsoft recommended block rules and noticed it is blocking a lot of application dlls. The blocked dll is frho...
Livi_1
Nov 14, 2022Copper Contributor
We're using device guard - windows defender application control (WDAC) along with a 3rd party endpoint detection (Malwarebytes). However we're running windows defender in passive mode.
Code integrity logs are enabled by default.
Code integrity logs are enabled by default.
HotCakeX
Feb 28, 2023MVP
Hi, the link you mentioned belongs to Applocker.
Microsoft recommended block rules are here:
https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules
and I searched for the DLL file you mentioned and couldn't find it in there.
When using a 3rd party AV, I suggest turning on EDR in Microsoft Defender in Windows and set it to block mode:
More info about WDAC and its deployment methods: (you don't need Applocker when using WDAC as WDAC is superior and provides more protection)
https://github.com/HotCakeX/Harden-Windows-Security/wiki/Introduction