AppLocker
Brief
Check
# check if it is running
Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections
# check which files/extensions are blacklisted/whitelisted:
Get-ApplockerPolicy -Effective -xml
$a = Get-ApplockerPolicy -effective
$a.rulecollectionsByPass
Default writeable folders
Alternate Data Stream
Last updated
