Top Tweets for #AaronLocker
@ASwisstone @samilaiho @kareldewinter @wmug @we_are_inspark Y'all *have* heard of #AaronLocker, right? Makes dealing with all those issues rather easy.
https://t.co/Z6BuFZNiP5
@notajungman @bettersafetynet @JimS83963080 @SwiftOnSecurity @olafhartong @BHinfoSecurity @securityonion AppLocker (where I live) doesn't block downloads but it blocks execution which ultimately is more important. WebEx drops its files into a user-writable location (under ProgramData IIRC); all files signed so you can allow in #AaronLocker with a few lines in TrustedSigners.ps1:
@mattifestation @danonit @0gtweet @rimpq ... which I asked them to change to static content to make it easier to reliably and accurate filter out the PSScriptPolicyTest events from #AaronLocker results based on file hash. Note that this isn't to WHITELIST them - it's just to ignore them when they turn up in the logs.
How to use Aaronlocker with Microsoft Intune #MSintune #Applocker #AaronLocker #Windows10 #Security https://t.co/hfj1qg2kHt


Big #AaronLocker app whitelisting update. More than a few people wanted graphs. But graphs of raw event counts are misleading. Solved: focus on NUMBER OF AFFECTED USERS instead. Also add field for hi-level location such as user profile or removable media. https://t.co/Z6BuFZNiP5
@arekfurt @Oddvarmoe I don't like executable code in user-writable directories, but Teams makes it very easy to whitelist its code, and #AaronLocker already does.
But this crap about "OMG update.exe will run arbitrary untrusted code!" is a non-issue. Already on the other side of the airtight hatchway
@SwiftOnSecurity And to their credit, the MS Teams team made it super easy to whitelist it: all the PE files are MS-signed and have the same product name. #AaronLocker already incorporates it.
https://t.co/Z6BuFZNiP5
@Oddvarmoe @xenosCR @MrUn1k0d3r @kevindienst Does the reverse-shell run if you have #AaronLocker - style whitelisting implemented? Whitelisting won't necessarily stop the download but should stop the execution.
@Vandenberghe_M @MarshallOfSound @LinuxCowsays @MrUn1k0d3r @atwolf #AaronLocker is stricter than that and doesn't allow *all* MS-signed executables, as that would be overly broad, including debuggers and other such tools. But it's easy to allow MS-signed TEAMS executables.
https://t.co/Z6BuFZNiP5
@markus_neis @MrUn1k0d3r @Hexacorn Sorry, I don't see the big deal here. By the time you do this, you already own the user's profile.
#AaronLocker addresses this quite nicely.
https://t.co/Z6BuFZNiP5
@Oddvarmoe @samilaiho @NestoriSyynimaa @MrUn1k0d3r WTF? Whitelisting, not blacklisting. Allow Microsoft-signed Teams executables but not other arbitrary crap. #AaronLocker already handles this.
https://t.co/Z6BuFZNiP5
@MrUn1k0d3r Did you try this with #AaronLocker configured? It allows Microsoft-signed Teams executables but not other crap you throw in there.
https://t.co/Z6BuFZNiP5
@aglerj @SwiftOnSecurity It's actually easy to whitelist Teams now because all the PE files are signed and have the same product name. #AaronLocker already incorporates it.
Some more improvements and fixes posted. If you downloaded a couple of days ago, download again. :)
#AaronLocker perf and feature updates - robust and practical application #whitelisting for #Windows, better and easier than ever. https://t.co/Q2zasL858r
Oh - and 15 years to the day since my first blog posts about running Windows as non-admin.
This is exactly one of the big use cases I think of when I recommend this kind of whitelisting: you hear about hospitals getting crushed by ransomware all the time, and it makes patient care extremely challenging.
#AaronLocker
https://t.co/BbxEOs09L3
https://t.co/Z6BuFZvHqv
@AaronMargosis @ahaak I'm mid rollout to 1,300 endpoints for regional rural hospital system. Self documenting and easy to make changes is fantastic. Your scripts make it thorough and precise. Your documentation made it possible to roll it out quickly and cross training my team was simple.
Several new updates to #AaronLocker -- automation for #AppLocker whitelisting. Now handles EXE/DLL files with non-standard extensions (e.g., .pyd); granularity options to intelligently reduce rule set size/complexity. https://t.co/Z6BuFZNiP5
@SwiftOnSecurity An example: #AaronLocker application whitelisting uses Excel all over the place, including for event analysis. https://t.co/Z6BuFZNiP5
Chrome's Pepper Flash 32 is using a new certificate with a different publisher. That'll break AaronLocker publisher rule for pepflashplayer.dll. Duplicate the rule in Allow-GoogleChromeFlashPlayer.xml and update publisher and id. #AppLocker #AaronLocker /cc @AaronMargosis

Most Popular Users

Elon Musk 
@elonmusk
241.5M followers

Barack Obama 
@barackobama
119M followers

Cristiano Ronaldo 
@cristiano
114M followers

Donald J. Trump 
@realdonaldtrump
111.8M followers

Narendra Modi 
@narendramodi
107.2M followers

Rihanna 
@rihanna
98.6M followers

NASA 
@nasa
92.4M followers

Justin Bieber 
@justinbieber
91.8M followers

KATY PERRY 
@katyperry
89.8M followers

Taylor Swift 
@taylorswift13
83.7M followers

Lady Gaga 
@ladygaga
75.2M followers

Virat Kohli 
@imvkohli
72.9M followers

Kim Kardashian 
@kimkardashian
70.8M followers

YouTube 
@youtube
68.8M followers

Neymar Jr 
@neymarjr
65.9M followers

Bill Gates 
@billgates
65M followers

Selena Gomez 
@selenagomez
62.8M followers

The Ellen Show
@theellenshow
62.3M followers

CNN 
@cnn
61.8M followers

X 
@x
60.7M followers




