Hi
I have Windows 10 Computers with a default Applocker Script rules in a GPO in AUDIT mode.
I see several warnings in the Applocker eventlog from all computers look like this:
%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\TEMP\WHDU3YAH.DXA.PS1 was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
The actual script files changes all the time and are not in the folder anymore when I check. Has anybody else seen this before?