windows-itpro-docs icon indicating copy to clipboard operation
windows-itpro-docs copied to clipboard

The hash in the rule is the part of the file that is calculated?

Open L0yy opened this issue 2 years ago • 1 comments

I can't match the vuln-driven file hash to any format hash in the rule, but it's definitely the same file. So I want to know where the hash value in the rule comes from and how it is calculated.


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

L0yy avatar Sep 07 '22 13:09 L0yy

Hi @L0yy, the hashes in the rules are PE/Authenticode hash rules. More info on these hashes are found here: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create#more-information-about-hashes

jgeurten avatar Sep 07 '22 20:09 jgeurten

@jgeurten Thank you very much for sharing this explanation. @L0yy Hope this comment is helpful for you. If you see a documentation update is required, please feel free to open an issue for the same. We proceed here to close it. Thanks for taking out some time to open the issue. Appreciate and encourage you to do the same in future also.

yogkumgit avatar Nov 02 '22 10:11 yogkumgit