From c814d08a84786daffb3e333aabd0405c874043b9 Mon Sep 17 00:00:00 2001 From: FRoGito Date: Fri, 18 Dec 2020 12:09:02 +0100 Subject: [PATCH] Mistakes correction in AppLocker lab --- .../Tools/IntroClass/AppLocker/AppLocker.md | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/IntroClassFiles/Tools/IntroClass/AppLocker/AppLocker.md b/IntroClassFiles/Tools/IntroClass/AppLocker/AppLocker.md index c3552838..d1f35252 100755 --- a/IntroClassFiles/Tools/IntroClass/AppLocker/AppLocker.md +++ b/IntroClassFiles/Tools/IntroClass/AppLocker/AppLocker.md @@ -12,8 +12,6 @@ Let’s get started by opening a Terminal as Administrator ![](attachments\Clipboard_2020-06-12-10-36-44.png) -![](attachments\Clipboard_2020-06-12-12-35-15.png) - When you get the User Account Control Prompt, select Yes. And, open a Ubuntu command prompt: @@ -121,6 +119,8 @@ This should generate a subset of rules for each group. It should look similar t ![](attachments\Clipboard_2020-06-12-13-00-24.png) +Only change the default rule so that the local administrators are not allowed to run all files anywhere. + Next, we need to enforce the rules: @@ -165,13 +165,9 @@ Now, let's surf to your Linux system, download the malware and try to run it aga +You should also get an error. - - - -You should get an error. - -To finish this lab, simply restart your class VM and log in as ADHD. +To finish this lab, simply disable AppLocker and restart your class VM to log in as ADHD.