Creating a Windows application filter to prevent running executables
In this example, we create a Windows application filter profile that prevents users from running Powershell, MS Paint, and other executables except in the %PROGRAMFILES%\*, %WINDIR%\* directories.
We then apply this Windows application filter to a non-privileged secret.
To create the Windows application filter:
- Setting up WinRM on the remote server
- Creating a target with server information as Windows
- Creating a Windows application filter profile
- Creating a privileged account secret
- Creating a non-privileged account
- Launching the secret