Skip to content

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant

  • Home
  • Post Series
    • WDAC
  • Links library
  • About
    • Home
    • KQL
Sentinel WDAC

January 2024 WDAC Advanced Hunting changes

Andrew 12 December 2023 0 Comments

Microsoft today published an update advisory for Windows Defender Application Control (WDAC) Advanced Hunting changes that could have an impact if you have any hunting rules or dashboards in place.…

Uncategorized WDAC

Confirm what WDAC policies are present on a device

Andrew 18 May 2022 0 Comments

Windows Defender Application Control (WDAC) is an application control system integrated into Windows 10/11 and is used within Enterprise to whitelist trusted applications, allowing them to run, and blocking either…

KQL Today I Learned

#TIL KQL parse_path() function

Andrew 5 May 2022 0 Comments

Working with Sentinel and Log Analytics is nearly a daily task for me of late, and working with WDAC of late interrogating file paths was something I was finding very…

You Missed

Microsoft Entra MIM2016

Looking to migrate from MIM to Microsoft Entra?

Sentinel WDAC

January 2024 WDAC Advanced Hunting changes

WDAC

Creating a policy with the WDAC Wizard

WDAC

Application control with Microsoft WDAC

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant