Forum Discussion

hari-siva's avatar
hari-siva
Copper Contributor
Aug 23, 2021

Block malware filehash values using applocker

Hi All, is there a way we can block malware filehash values using Applocker GPO without having to locate or have a actual copy of the malware file ? appreciate your response... cheers.. 

8 Replies

  • scsecurium's avatar
    scsecurium
    Copper Contributor

    hari-siva  Malware threats and related cyberattacks have increased eventually. That's why cybersecurity awareness has become essential in today's generation. So, I would suggest for https://securiumsolutions.org/ to avoid such circumstances in the future.

  • Reza_Ameri's avatar
    Reza_Ameri
    Silver Contributor
    AppLocker is NOT a replacement for Anti-Malware product and to set a policy, you will need to have a sample of it.
    However, you may do it other way, like create a whitelist and only add trusted applications and place the rest into black list, so it will block everything else.
    In case it is a malware, you may report it to Microsoft Anti-Malware team to create a signature. You may upload it to websites where they product hash key.
  • https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/import-an-applocker-policy-into-a-gpo
    Hello , I think the malware mechanisms are working not visible
    and group rules will not be effective!
    • hari-siva's avatar
      hari-siva
      Copper Contributor
      thanks Andrzej1 , let me check it and advise..