Application Whitelist Auditor

Discussion in 'other software & services' started by WildByDesign, Jun 12, 2017.

  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Nope
     
  2. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I got control of the mouse cursor, finally. Here is the screenshot that couldn't include in my post last night.

    Airlock Digital_Application Whitelist Auditor_21.JPG
     
  3. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295

    Attached Files:

  4. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Very cool... yeah, I have played with this a little more as well.

    I tested the differences between a SUA and an Admin account, and the results appeared to be identical. There were TONS of folders where the exe samples executed, so there was really no way to check them all, but I believe the results were the same.

    What were you testing above? I tested VS a few more times, and had the same results.

    C:\Windows\System32\Tasks
    C:\Windows\SysWOW64\Tasks
    C:\Windows\Tasks
    C:\Windows\Temp

    This is a pretty cool test... I just would not recommend running it on your main computer... it might put crap everywhere ;).
     
  5. danielschell

    danielschell Registered Member

    Joined:
    Jul 18, 2017
    Posts:
    2
    Location:
    Adelaide
    That's me. Just came across this thread :)

    We're starting to plan the next version of the whitelist auditor. Something that hasn't been discussed heavily here is the DLL enforcement, however it looks like there's not to many Applocker people here.

    I'll add this to roadmap for the tool. If anyone has any other feature requests please reach out :)
     
  6. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Very cool... if I think of anything else to add, I will let you know... cool app btw!

    Sorry it has taken me a while to reply... things have been a little busy.
     
  7. danielschell

    danielschell Registered Member

    Joined:
    Jul 18, 2017
    Posts:
    2
    Location:
    Adelaide
    No worries - I just got back from the US Summer hacker camp :)

    Also added to the roadmap for the tool is DeviceGuard enumeration and handling blocked DLLs better.
     
  8. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    An interesting addition here...

    Airlock Application Whitelisting Word Macro Security Auditor v1.0
    Link: https://twitter.com/danonit/status/897434357341736960
    Download: https://www.airlockdigital.com/AirlockApps/Airlock_Application_Whitelisting_Macro_Security_Auditor_v1.0.doc
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.