UltimateAppLockerByPassList icon indicating copy to clipboard operation
UltimateAppLockerByPassList copied to clipboard

RUNDLL32.EXE

Open amandaw33 opened this issue 6 years ago • 5 comments

heads up for me blocking %SYSTEM32%\RUNDLL32.EXE by publisher caused pinned items to stop working on win10 1809.

thanks for all your work on these rules.

amandaw33 avatar Feb 20 '20 15:02 amandaw33

Thanks for the info. Note that blocking rundll32 is not supported and it is kinda expected that it will break something.

api0cradle avatar Feb 20 '20 21:02 api0cradle

It's listed here, no? Sorry if I'm misunderstanding.

https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/AppLocker-BlockPolicies/PublisherBlockRules-EXE.xml

amandaw33 avatar Feb 20 '20 22:02 amandaw33

image

api0cradle avatar Feb 20 '20 22:02 api0cradle

I have added it, but I do not recommend the blocking rules to be used actively in production without proper testing since it might actually break stuff. The most scary binary is the rundll32 for sure

api0cradle avatar Feb 20 '20 22:02 api0cradle

Thanks just wanted to make sure I wasn't misunderstanding the rules set. I did test, then moved it to prod and ran it for a week before anyone noticed 😁 cheers!

amandaw33 avatar Feb 20 '20 22:02 amandaw33