Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RUNDLL32.EXE #16

Open
amandaw33 opened this issue Feb 20, 2020 · 5 comments
Open

RUNDLL32.EXE #16

amandaw33 opened this issue Feb 20, 2020 · 5 comments

Comments

@amandaw33
Copy link

heads up for me blocking %SYSTEM32%\RUNDLL32.EXE by publisher caused pinned items to stop working on win10 1809.

thanks for all your work on these rules.

@api0cradle
Copy link
Owner

Thanks for the info. Note that blocking rundll32 is not supported and it is kinda expected that it will break something.

@amandaw33
Copy link
Author

@api0cradle
Copy link
Owner

image

@api0cradle
Copy link
Owner

I have added it, but I do not recommend the blocking rules to be used actively in production without proper testing since it might actually break stuff. The most scary binary is the rundll32 for sure

@amandaw33
Copy link
Author

Thanks just wanted to make sure I wasn't misunderstanding the rules set. I did test, then moved it to prod and ran it for a week before anyone noticed 😁 cheers!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants