windows-itpro-docs/windows/keep-secure/understanding-the-file-hash-rule-condition-in-applocker.md
Jan Backstrom 8e6dba25e9 update tagging
change W10 to w10 (lower case); add ms.pagetype; added authors
2016-05-27 13:46:06 -07:00

1.4 KiB

title, description, ms.assetid, ms.prod, ms.mktglfcycl, ms.sitesec, ms.pagetype, author
title description ms.assetid ms.prod ms.mktglfcycl ms.sitesec ms.pagetype author
Understanding the file hash rule condition in AppLocker (Windows 10) This topic explains the AppLocker file hash rule condition, the advantages and disadvantages, and how it is applied. 4c6d9af4-2b1a-40f4-8758-1a6f9f147756 w10 deploy library security brianlic-msft

Understanding the file hash rule condition in AppLocker

Applies to

  • Windows 10

This topic explains the AppLocker file hash rule condition, the advantages and disadvantages, and how it is applied.

File hash rules use a system-computed cryptographic hash of the identified file. For files that are not digitally signed, file hash rules are more secure than path rules. The following table describes the advantages and disadvantages of the file hash condition.

File hash condition advantages File hash condition disadvantages
Because each file has a unique hash, a file hash condition applies to only one file. Each time that the file is updated (such as a security update or upgrade), the file's hash will change. As a result, you must manually update file hash rules.
 
For an overview of the three types of AppLocker rule conditions and explanations of the advantages and disadvantages of each, see Understanding AppLocker rule condition types.