Microsoft-Windows-SoftwareRestrictionPolicies
6 events across 1 channel
Event ID 50 — Access to AttemptedPath is monitored by policy rule SrpRuleGuid.
Event ID 865 — Access to AttemptedPath has been restricted by your Administrator by the default software restriction policy level.
Description
Access to AttemptedPath has been restricted by your Administrator by the default software restriction policy level.
Message #
Fields #
| Name | Description |
|---|---|
AttemptedPath UnicodeString | — |
Detection Patterns #
Execution: Software Deployment Tools
SoftwareRestrictionPolicies Event ID 865: Access to AttemptedPath has been restricted by your Administrator by the default software restriction policy level.OREvent ID 866: Access to AttemptedPath has been restricted by your Administrator by location with policy rule SrpRuleGuid placed on path RulePath.OREvent ID 867: Access to AttemptedPath has been restricted by your Administrator by software publisher policy.OREvent ID 868: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.OREvent ID 882: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.
1 rule
Event ID 866 — Access to AttemptedPath has been restricted by your Administrator by location with policy rule SrpRuleGuid placed on path RulePath.
Description
Access to AttemptedPath has been restricted by your Administrator by location with policy rule SrpRuleGuid placed on path RulePath.
Message #
Fields #
| Name | Description |
|---|---|
AttemptedPath UnicodeString | — |
SrpRuleGuid GUID | — |
RulePath UnicodeString | — |
Detection Patterns #
Execution: Software Deployment Tools
SoftwareRestrictionPolicies Event ID 865: Access to AttemptedPath has been restricted by your Administrator by the default software restriction policy level.OREvent ID 866: Access to AttemptedPath has been restricted by your Administrator by location with policy rule SrpRuleGuid placed on path RulePath.OREvent ID 867: Access to AttemptedPath has been restricted by your Administrator by software publisher policy.OREvent ID 868: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.OREvent ID 882: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.
1 rule
Event ID 867 — Access to AttemptedPath has been restricted by your Administrator by software publisher policy.
Description
Access to AttemptedPath has been restricted by your Administrator by software publisher policy.
Message #
Fields #
| Name | Description |
|---|---|
AttemptedPath UnicodeString | — |
Detection Patterns #
Execution: Software Deployment Tools
SoftwareRestrictionPolicies Event ID 865: Access to AttemptedPath has been restricted by your Administrator by the default software restriction policy level.OREvent ID 866: Access to AttemptedPath has been restricted by your Administrator by location with policy rule SrpRuleGuid placed on path RulePath.OREvent ID 867: Access to AttemptedPath has been restricted by your Administrator by software publisher policy.OREvent ID 868: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.OREvent ID 882: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.
1 rule
Event ID 868 — Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.
Description
Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.
Message #
Fields #
| Name | Description |
|---|---|
AttemptedPath UnicodeString | — |
SrpRuleGuid GUID | — |
Detection Patterns #
Execution: Software Deployment Tools
SoftwareRestrictionPolicies Event ID 865: Access to AttemptedPath has been restricted by your Administrator by the default software restriction policy level.OREvent ID 866: Access to AttemptedPath has been restricted by your Administrator by location with policy rule SrpRuleGuid placed on path RulePath.OREvent ID 867: Access to AttemptedPath has been restricted by your Administrator by software publisher policy.OREvent ID 868: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.OREvent ID 882: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.
1 rule
Event ID 882 — Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.
Description
Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.
Message #
Fields #
| Name | Description |
|---|---|
AttemptedPath UnicodeString | — |
SrpRuleGuid GUID | — |
Detection Patterns #
Execution: Software Deployment Tools
SoftwareRestrictionPolicies Event ID 865: Access to AttemptedPath has been restricted by your Administrator by the default software restriction policy level.OREvent ID 866: Access to AttemptedPath has been restricted by your Administrator by location with policy rule SrpRuleGuid placed on path RulePath.OREvent ID 867: Access to AttemptedPath has been restricted by your Administrator by software publisher policy.OREvent ID 868: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.OREvent ID 882: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid.