A Few Questions Regarding Appguard, Applocker, and EMET.

Discussion in 'other anti-malware software' started by CrusherW9, Dec 27, 2012.

Thread Status:
Not open for further replies.
  1. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    Very nice Kees :) :thumb:

    although, and I hope I'm wrong for your sake, I think the SRP policy settings will be ignored because you are running both AppLocker and SRP simultaneously within the same system. I know it works this way when they are enabled within the same domain.
     
  2. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    I have tested this: AppLocker rules overrule SRP rules, so EXE, COM and MSI are handled by AppLocker, all other executable extensions are handled by SRP. Main reason is that DLL rules with AppLocker seem to have an impact on system performance (on my 2008 low spec dual core).


    Sequence of security interaction (according to my testing):

    1st: Open File security warning (or block wth 1806 trick): file originating from Internet
    2nd: Access Control List: "deny execute file/tracerse folder" generates a deny "Windows cannot access the specified ....etc. "
    3rd: UAC (e.g. when deny elevation of unsigned is enabled)
    4th: AppLocker
    5th: SRP

    Who needs third party security when owning an Ultimate Version :D
     
    Last edited: Jan 5, 2013
  3. Gobbler

    Gobbler Registered Member

    Joined:
    Jul 30, 2010
    Posts:
    270
    Have you tried executing scripts? The reason I am asking this because I tried applying Applocker/SRP the very same way you have but upon enabling Applocker, SRP no longer blocks scripts as it should because SRP was supposed to look over script executions and Applocker executables and MSI files, am i missing something?
     
  4. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Gobbler, see picture SRP does not prevent other executable formats from running, so I will drop SRP and only rely on AppLocker. Thx
     

    Attached Files:

  5. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    I think I have mentioned that before in some other thread (that SRP won't work when AppLocker is enabled)... but no one ever believes me... lol
     
  6. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    True, you mentioned it. It is not that I don't believe you, I trusted the Microsoft info telling that AppLocker rules overruled SRP rules, :oops:

    it took some to learn and test thanks to Gobbler, :blink:

    AppLocker ONLY from now on :cool:
     

    Attached Files:

  7. Gobbler

    Gobbler Registered Member

    Joined:
    Jul 30, 2010
    Posts:
    270
    u r welcome :)
     
  8. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    Good to see you got it all sorted, Kees :)

    My thoughts exactly :thumb: Well, almost...I use EMET and currently Jetico firewall :shifty:
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.