How to 'Virus-Proof' Your Computer With Windows AppLocker (Ultimate Guide)

preview_player
Показать описание
Well, at least as close to virus-proof as you can get... 🤔

(Current resource pack version = 6, Updated 2/14/2024)

📝Additional Notes:
• To get AppLocker policies to actually work, you might have to enable the "Application Identity" service and set it to start automatically if it isn't already. This requires a special command because it is a protect process (as opposed to just opening the services menu). To do this, run the command in command prompt as admin:
• I figured this went without saying, but obviously if you download something malicious and add a rule to allow it, you will be infected. You still must ALWAYS be vigilant. And you should still also use an Antivirus, it’s not a replacement for that.

▼ Time Stamps: ▼
0:00 - Intro
2:21 - Video Chapters Outline
3:37 - Creating a Shortcut to AppLocker
5:17 - AppLocker Initial Setup
6:17 - Creating AppLocker Log in Event Viewer
9:02 - AppLocker Default Rules
10:44 - File Types For Different Rule "Collections"
12:26 - Adding Rules & How They Work
26:10 - Deny Rules
27:22 - More Rules I Added
31:17 - Allowing Specific Signed Files
32:30 - Why Add Rules Blocking PowerShell?
35:27 - Importing the Policy
36:10 - Note About "Policy Test" Files
36:52 - Note If You Don't Have PowerShell 7
37:41 - AppLocker With Powershell (IMPORTANT)
40:33 - Disabling PowerShell 2.0
40:59 - Setting PowerShell Execution Policy
43:54 - Blocking Bypass of Execution Policy
46:05 - PowerShell Script Block Logging
46:57 - PowerShell 7 Has Separate Execution Policies
47:36 - Setting Up PowerShell 7 Execution Policies
49:46 - Which PowerShell MachinePolicy Should You Use?
50:30 - How to Determine if a File is Signed
51:38 - Wrapping Up

Corrections:
@ 47:52 - If you don't have PowerShell 7 installed, you actually still can add the settings to Group Policy Editor. See instructions in the 'ReadMe' file in the resource pack in the description.

▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
Рекомендации по теме
Комментарии
Автор

I knew the video would be longer than average but not this long 😩
📝Notes:
• Also I figured this went without saying, but obviously if you download something malicious and add a rule to allow it, you will be infected. You still must ALWAYS be vigilant. And you should still also use an Antivirus, it’s not a replacement for that.
• To get AppLocker policies to actually work, you might have to enable the "Application Identity" service and set it to start automatically if it isn't already. This requires a special command because it is a protect process (as opposed to just opening the services menu). To do this, run the command in command prompt as admin:
sc.exe config appidsvc start= auto
• Turns out you CAN actually add the Group Policy settings for PowerShell core without having to install PowerShell Core. I've added instructions to the ReadMe file in the resource pack in the description, but basically you download the latest zip release from Microsoft's PowerShell GitHub, and copy the files and into the directories and respectively.

ThioJoe
Автор

I don't know why everybody is emphasizing the duration of this video - for me - it was like watching a super interesting, informative and well-written documentary - the time just flew buy! Excellent work, thank you so much for your effort! Greetings from Croatia :)

nikolamilasevic
Автор

let's appreciate how much effort this guy spent to help us virus-proof our computers

aaaaaaaaaaaaaaaaaaaaaaa
Автор

The hero we didn't know we deserved

MVIE
Автор

Hey ThioJoe! I appreciate you making this more detailed and longer! 🎉

FladeTV
Автор

Here's what I did for my grandma's PC, very simple:

- Require my own password for Administrative privileges so she can't do that
- Set up a single browser so she has no access to other browsers, with downloads always dropping into the Downloads folder
- Wrote a script to instantly delete any executables that enter the Downloads folder

My beloved virus addict is now sober :)

hoffer_moment
Автор

This is amazing, thanks so much for taking the time and putting so much effort into this. You're a legend!

DavidKing
Автор

I swear this video is so informative and useful it’s something you could probably charge for and make thousands off of but you were nice enough to give it to everyone for free, what a guy

Galactum
Автор

Congrats on 3M subscribers! Well deserved!

craz
Автор

You know @ThioJoe has a gift for teaching and explaining when the whole 50 minute video felt like 10 and you remember fairly well most of the process!
Totally appreciate this video.

Mikesco
Автор

I think this is your second longest video. Nothing beats that 2 hour one

_SJ
Автор

I have no intention to do any of this myself but I watched it all
You made it very engaging and informative, I didn't noticed the length until it was almost done
I wont mind more "complex" tutorials like this on in the future

GianniLeonhart
Автор

Best 50 minute of my time, thanks a lot TJ, definitely learned a lot.

nicholashoi
Автор

This is one of those videos that I've saved up to watch, as you were asking in a recent poll. Thanks for the detailed explanation!

prince_julius
Автор

We've been waiting! Thank you Thio!! 🎉🎉🎉

orangecat
Автор

one of the best tutorials for applocker, even one of the most in-depth well explained tutorial in general

homerwrld
Автор

@thiojoe, this was one of the best mapped out videos covering a relatively complex topic and one with lots of settings. We are implementing this, and your video has been shared to the team as the best tutorial about it.

schapman
Автор

Awesome video ThioJoe! Structured well like a course. 👍

S-axle
Автор

Exactly what I was waiting for 🎉 Many, many thanks Thio ✌️

ionamygdalon
Автор

THANK YOU SO MUCH! I've been waiting for a tutorial on how to set this up.
Great video as always!

qazx-mprv