47 Commits

Author SHA1 Message Date
Jordan Geurten
62c512b1a4
Merge branch 'main' into jgeurten-update-recommended-driver-blocklist 2024-08-23 10:46:11 -04:00
Joel Tuckwell
20e9cdb8e7
Update applications-that-can-bypass-wdac.md to fix MSBuild.exe original filename case
Fixed the filename for FileName=MSBuild.exe to match the Original Filename in the file metadata, rather than just the file name on disk. 

This fixes case sensitive blocklist rules in security products using Original Filenames built off of this XML.
2024-08-19 16:16:08 +09:30
Jordan Geurten
688318ac83 Updated the published blocklist with August updates 2024-08-15 13:01:11 -04:00
Vinay Pamnani (from Dev Box)
f5963a72d6 Update ms.topic 2024-06-07 10:13:34 -06:00
Aaron Czechowski
53a840b602
Merge pull request #11900 from HotCakeX/patch-4
Removed the note about not using UTF-8 encoding for certificate fields and merged 2 Notes
2024-05-21 09:38:52 -07:00
Violet
e5b7045d72
Removed the note about not using UTF-8 encoding for certificate fields
The note is no longer necessary, confirmed here:
https://github.com/MicrosoftDocs/windows-itpro-docs/pull/11889#issuecomment-2105289949
2024-05-18 13:14:14 +03:00
Violet
5de76c4148
The Unsigned policy rule option is valid for Supplemental types 2024-05-16 12:50:06 +03:00
Jeff Borsecnik
a6b4d08cb9
Update deploy-multiple-wdac-policies.md - reformat note 2024-04-17 10:27:13 -07:00
Jordan Geurten
b24cf72e08 added note about win 11 21h2 2024-04-16 18:50:26 -04:00
Jordan Geurten
e8b6169893 Corrected dates 2024-04-15 11:55:03 -04:00
Jordan Geurten
eb25aa7a36 Reapply "Updated policy limit information to reflect current state. Fixed acro…"
This reverts commit 19377758673e71db9440cff844f82beb428f84d8.
2024-04-15 11:51:14 -04:00
jsuther1974
1937775867
Revert "Updated policy limit information to reflect current state. Fixed acro…" 2024-03-14 09:34:25 -07:00
jsuther1974
3615a251e2
Merge branch 'main' into WDAC-Docs 2024-03-13 13:01:03 -07:00
jsuther1974
78ea6aa008 Updated policy limit information to reflect current state. Fixed acrolinx issues 2024-03-13 13:00:11 -07:00
Paolo Matarazzo
1459fe386a Merge branch 'main' of github.com:MicrosoftDocs/windows-docs-pr into pm-20240124-kiosk 2024-03-13 08:29:26 -04:00
Mohammed Tanveer
60e1bd1a42
Update applications-that-can-bypass-wdac.md
Sorted <FileRules> list alphabetically & included an RuleID for <Signers /> scenario as well.
2024-02-27 18:56:34 +05:30
Mohammed Tanveer
904909a5dc
Update applications-that-can-bypass-wdac.md
Included dbgsrv.exe to the ruleset that was missing & a known WDAC bypass.
2024-02-08 11:29:19 +05:30
Paolo Matarazzo
9ac14a95ea Update references to non-Microsoft solutions in identity protection and encryption 2024-02-05 15:04:15 -05:00
Jordan Geurten
cf6392a820 Acrolinx feedback 2024-01-24 12:56:50 -05:00
Jordan Geurten
f04f33d8cd Drive-by update of the MDE AH query for the WDAC Wizard 2024-01-12 17:31:46 -05:00
Jordan Geurten
71bcf76620 Added a link for the policy xml files to be downloaded 2024-01-12 15:34:18 -05:00
Jordan Geurten
73c60df054 Added up to 2312 blocks to the recommended blocklist 2024-01-12 15:19:44 -05:00
jsuther1974
071052fc2d
Update windows/security/application-security/application-control/windows-defender-application-control/design/plan-wdac-management.md
Co-authored-by: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com>
2023-11-22 10:53:19 -08:00
jsuther1974
018be943ca Added known issues for audit mode and fixed some issues in articles 2023-11-22 10:14:12 -08:00
Paolo Matarazzo
4ae3910efe metadata updates 2023-11-13 10:25:14 -05:00
Jordan Geurten
2d52c00366 fixed bolding 2023-10-18 15:03:19 -04:00
Jordan Geurten
c8bac6cd23 one more time.. 2023-10-18 14:54:34 -04:00
Jordan Geurten
381b00880e Fixed typo and broken link 2023-10-18 14:50:16 -04:00
Jordan Geurten
4534714fcd Corrected description with official language 2023-10-18 13:57:44 -04:00
Jordan Geurten
20c671fdf6 documented developer mode dynamic code trust 2023-10-18 13:44:21 -04:00
Jordan Geurten
da7de5b5ae Added new rules and updates since 2309 2023-10-16 12:47:35 -04:00
Jordan Geurten
2eb9aacb29 Updated CPUZ block to 156 2023-09-06 18:16:25 -04:00
Jordan Geurten
e3e952f3e7
Merge branch 'main' into jgeurten-vulnerable-driver-block-rules-2308 2023-09-06 16:25:00 -04:00
Jordan Geurten
4d798e91c5 Recommended blocks only (not in inbox list) 2023-08-21 15:31:16 -04:00
Jordan Geurten
010530ac9a Added new driver block rules from previous iterations updates 2023-08-21 15:17:21 -04:00
Aaron Czechowski
2fdf333a01 add must-keep collection 2023-08-18 17:14:33 -07:00
Paolo Matarazzo
80c8bc4e5d removed licensing info 2023-08-16 07:18:42 -04:00
Stephanie Savell
9000507ab8
Update windows/security/application-security/application-control/windows-defender-application-control/design/select-types-of-rules-to-create.md 2023-08-14 12:59:47 -05:00
jsuther1974
b6af2c1270 Removed claim that user writeable check is done recursively for parent directories. 2023-08-11 09:38:05 -07:00
Jordan Geurten
542300d0d0 Fixed unsigned policy valid supplemental option 2023-08-04 13:42:40 -04:00
Vinay Pamnani
9f04afe6e3 Changed Microsoft Recommended Block list article 2023-08-01 10:18:38 -04:00
Vinay Pamnani
75819ce390 Rename Windows Security app 2023-07-31 15:21:40 -04:00
Vinay Pamnani
6fbc9db475
Update wdac-and-dotnet.md 2023-07-26 10:23:22 -04:00
Vinay Pamnani
59f4147942 Metadata updates 2023-07-17 12:51:43 -04:00
Vinay Pamnani
d78a5dd183 Fix licensing links 2023-07-17 12:45:50 -04:00
Vinay Pamnani
d755cc90c3 Rename files, Fix links 2023-07-17 12:37:16 -04:00
Vinay Pamnani
dad6503292 Move files 2023-07-13 11:53:45 -04:00