Detection rules › Sigma
Restricted Software Access By SRP
Detects restricted access to applications by the Software Restriction Policies (SRP) policy
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Execution | T1072 Software Deployment Tools |
| Lateral Movement | T1072 Software Deployment Tools |
Event coverage
Stages and Predicates
Stage 1: selection
Provider_Name: 'Microsoft-Windows-SoftwareRestrictionPolicies'
Indicators
Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.
| Field | Kind | Values |
|---|---|---|
Provider_Name | eq |
|