MicrosoftDocs / WDAC-Toolkit

Documentation and tools to access Windows Defender Application Control (WDAC) technology.
Creative Commons Attribution 4.0 International
201 stars 43 forks source link

Convert supplemental xmls to binary policies to deploy #414

Closed jgeurten closed 1 month ago

jgeurten commented 1 month ago

The event log parsing workflow now converts event logs to supplemental policies with:

  1. Base Policy Id set to the most common policy ID in the audit/block events
  2. A unique Policy Id
  3. Parameters to convert a supplemental xml to cip

The Wizard now offers the ability to convert the xml to cip if the setting is enabled in the Settings Menu