diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-operational-guide.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-operational-guide.md index 2227143aad..8a7ad0700f 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-operational-guide.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-operational-guide.md @@ -32,8 +32,9 @@ WDAC generates and logs events when a policy is loaded as well as when a binary WDAC events are generated under two locations: -1. Applications and Services logs – Microsoft – Windows – CodeIntegrity – Operational -2. Applications and Services logs – Microsoft – Windows – AppLocker – MSI and Script + - Applications and Services logs – Microsoft – Windows – CodeIntegrity – Operational + + - Applications and Services logs – Microsoft – Windows – AppLocker – MSI and Script ## In this section