Skip to content

2 blocks from WDAC, on WHH Light  #21

@shmu26

Description

@shmu26

I got two blocks after enabling WDAC. The first one is wsl, which you already explained to me that it is blocked by design. But I have no idea where the second block is coming from.

`******** WDAC blocked events for EXE and DLL files ********
***********************************************************




Event[0]:
Event Id = 3077
Local Time:  2024/04/08 19:58:55
Attempted Path = C:\Windows\System32\wsl.exe
Parent Process = C:\Program Files\WindowsApps\CanonicalGroupLimited.Ubuntu_2204.3.49.0_x64__79rhkp1fndgsc\ubuntu.exe
PolicyName = UserSpace Lock
UserWriteable = false


***********************************************************
***********************************************************


Event[1]:
Event Id = 3077
Local Time:  2024/04/08 19:56:10
Attempted Path = C:\Windows\System32\wsl.exe
Parent Process = C:\Program Files\WindowsApps\CanonicalGroupLimited.Ubuntu_2204.3.49.0_x64__79rhkp1fndgsc\ubuntu.exe
PolicyName = UserSpace Lock
UserWriteable = false


***********************************************************
***********************************************************


Event[2]:
Event Id = 3077
Local Time:  2024/04/08 19:42:22
Attempted Path = C:\Windows\SysWOW64\wbem\WMIC.exe
Parent Process = C:\Windows\SysWOW64\cmd.exe
PolicyName = UserSpace Lock
UserWriteable = false


***********************************************************
***********************************************************`

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions