{"repo":"techspence/AppLockerInspector","free":true,"listed":false,"github":"https://github.com/techspence/AppLockerInspector","clone":"git clone https://github.com/techspence/AppLockerInspector.git","description":"Audits an AppLocker policy XML and reports weak/misconfigured/risky settings, including actual ACL checks.","language":"PowerShell","stars":152,"topics":["application-control","applocker","microsoft","powershell","windows"],"license":null,"category":"cli-tools","readme_excerpt":"AppLocker Inspector audits an AppLocker policy XML and reports weak/misconfigured/risky settings, including actual ACL checks. If you don’t provide a policy file, the tool will export the local effective AppLocker policy and analyze that automatically. Disclaimer: ChatGPT, my coding partner in \"crime\", wrote most of this. It's been heavily edited by me to remove as much sillyness as I could find and to make it more readable. However, if anyone finds anything wacky, please let me know so I can fix it! Hope it's useful to some people! 🙌 ---- Get even MORE detail from MagicSword Want to convert AppLocker policies to WDAC compatible policies AND get a report of all the dangerous misconfigs in your policy? 👉 Check out MagicSword Here's 4 neat things to know about MagicSword: - It's designed around threat-intel & security research (not just deny all) - It's optimized onboarding gets you up and running quickly - No SOC required - Agentless Disclaimer: The folks at MagicSword are friends. I am not paid for this shoutout. They just have a super cool project and I want to help them get the word out!! p.s.: If you want to try it out, DM me for a discount code ---- Features - Policy acquisition - If -Path is omitted, collects the local effective policy via Get-AppLockerPolicy -Effective -Xml , saves it to disk, and audits it. - Collection posture checks - Flags NotConfigured and AuditOnly collections (EXE, DLL, Script, MSI, Packaged app). - Rule risk detection - Broad principals: Every","default_branch":null,"files":null,"tree":[],"storefront":"/r/techspence","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/techspence/AppLockerInspector/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}