Forum Discussion

Livi_1's avatar
Livi_1
Copper Contributor
Nov 06, 2022

Microsoft recommended block rules for DLLs

Has anyone has experience working with the DLL rules.

 

Currently we have implemented Microsoft recommended block rules and noticed it is blocking a lot of application dlls. The blocked dll is frhook.dll.

 

Our initial thoughts would be that these dlls would be included within the microsoft allowed dll's, however I think that might not be the case. Does anyone know what is within the list of allowed DLLs within the Microsoft block rules?

 

An example from the code integrity logs is:

Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\FRHook.dll that did not meet the Windows signing level requirements.

 

Reference: DLL rules in AppLocker (Windows) - Windows security | Microsoft Learn

Share

Resources