Name:Windows AppLocker Block Events id:e369afe8-cd35-47a3-9c1e-d813efc1f7dd version:9 date:2026-04-15 author:Michael Haag, Splunk status:production type:Anomaly Description:The following analytic detects attempts to bypass application restrictions by identifying Windows AppLocker policy violations. It leverages Windows AppLocker event logs, specifically EventCodes 8007, 8004, 8022, 8025, 8029, and 8040, to pinpoint blocked actions. This activity is significant for a SOC as it highlights potential unauthorized application executions, which could indicate malicious intent or policy circumvention. If confirmed malicious, this activity could allow an attacker to execute unauthorized applications, potentially leading to further system compromise or data exfiltration. Data_source:
search:`applocker` EventCode IN (8007, 8004, 8022, 8025, 8029, 8040)
| spath input=UserData_Xml
| rename RuleAndFileData.* as *, TargetUser as user, Computer as dest
| stats count min(_time) as firstTime max(_time) as lastTime BY dest, PolicyName, RuleId, user, TargetProcessId, FilePath, FullFilePath, EventCode