Forum Discussion
Block malware filehash values using applocker
Hi All, is there a way we can block malware filehash values using Applocker GPO without having to locate or have a actual copy of the malware file ? appreciate your response... cheers..
8 Replies
- scsecuriumCopper Contributor
hari-siva Malware threats and related cyberattacks have increased eventually. That's why cybersecurity awareness has become essential in today's generation. So, I would suggest for https://securiumsolutions.org/ to avoid such circumstances in the future.
- Reza_AmeriSilver ContributorAppLocker is NOT a replacement for Anti-Malware product and to set a policy, you will need to have a sample of it.
However, you may do it other way, like create a whitelist and only add trusted applications and place the rest into black list, so it will block everything else.
In case it is a malware, you may report it to Microsoft Anti-Malware team to create a signature. You may upload it to websites where they product hash key.- hari-sivaCopper ContributorThanks Reza_Ameri.
- Reza_AmeriSilver ContributorWelcome, glad it was helpful
- EricStarkerFormer Employee
Hello! You've posted your question in the Tech Community Discussion space, which is intended for discussion around the Tech Community website itself, not product questions. I'm moving your question to the Windows security space- please post Windows security questions here in the future.
(If I am incorrect on the topic you are asking about, please let me know.)
- hari-sivaCopper Contributorthanks Eric.
- Deletedhttps://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/import-an-applocker-policy-into-a-gpo
Hello , I think the malware mechanisms are working not visible
and group rules will not be effective!- hari-sivaCopper Contributorthanks Andrzej1 , let me check it and advise..