﻿<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved.">
  <assemblyIdentity name="Microsoft-Windows-AppIDCore" version="10.0.10586.122" processorArchitecture="amd64" language="neutral" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
  <dependency discoverable="no" resourceType="resources">
    <dependentAssembly dependencyType="prerequisite">
      <assemblyIdentity name="Microsoft-Windows-AppIDCore.Resources" version="10.0.10586.122" processorArchitecture="amd64" language="*" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
    </dependentAssembly>
  </dependency>
  <file name="appid.sys" destinationPath="$(runtime.drivers)\" sourceName="appid.sys" sourcePath=".\" importPath="$(build.nttree)\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <signatureInfo xmlns="urn:schemas-microsoft-com:asm.v3">
      <signatureDescriptor pageHash="true" />
    </signatureInfo>
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">mNEo0eb6Jw7Zrb/lAHj2inlMANTLuG4o7GFh/60MqP8=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="srpapi.dll" destinationPath="$(runtime.system32)\" sourceName="srpapi.dll" sourcePath=".\" importPath="$(build.nttree)\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">vnbZFyxjW7Zo9+tyED9Mws+TkvzjUEOLfkIwmbAziuA=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="AppLockerCSP.dll" destinationPath="$(runtime.system32)\" sourceName="AppLockerCSP.dll" sourcePath=".\" importPath="$(build.nttree)\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">z1ukOaJ+gPzieWuxYJY945JH3aP6f8GCTX8JNvl4AgA=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <directories>
    <directory destinationPath="$(runtime.system32)\AppLocker\" owner="false">
      <securityDescriptor name="APPID_SERVICE_ALL_ACCESS_DIRECTORY" />
    </directory>
  </directories>
  <memberships>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories.Services" version="10.0.10586.122" publicKeyToken="31bf3856ad364e35" typeName="Service" />
      <categoryInstance>
        <serviceData name="AppID" displayName="@%systemroot%\system32\srpapi.dll,-100" errorControl="normal" imagePath="system32\drivers\appid.sys" start="demand" type="kernelDriver" description="@%systemroot%\system32\srpapi.dll,-101" dependOnService="FltMgr" />
      </categoryInstance>
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="BootRecovery" />
    </categoryMembership>
  </memberships>
  <registryKeys>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AppID\Parameters">
      <registryValue name="DebugFlags" valueType="REG_DWORD" value="0x00000000" />
      <securityDescriptor name="APPID_SERVICE_ALL_ACCESS_AND_BU_READ_ACCESS" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\AppID">
      <securityDescriptor name="APPID_SERVICE_ALL_ACCESS_AND_BU_READ_ACCESS" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\AppID\CertStore">
      <securityDescriptor name="APPID_SERVICE_ALL_ACCESS" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\AppID\CertChainStore">
      <securityDescriptor name="APPID_SERVICE_ALL_ACCESS" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{498A0351-BA2F-46DD-96D9-C19988FEA0C4}\InProcServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\AppLockerCsp.dll" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Free" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{deca92e0-af85-439e-9204-86679978da08}">
      <registryValue name="" valueType="REG_SZ" value="EDP Policy Manager Task Handler" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{deca92e0-af85-439e-9204-86679978da08}\InProcServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\AppLockerCsp.dll" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Free" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\csps\.\Vendor\MSFT\AppLocker">
      <registryValue name="" valueType="REG_SZ" value="{498A0351-BA2F-46DD-96D9-C19988FEA0C4}" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
  </registryKeys>
  <trustInfo>
    <security>
      <accessControl>
        <securityDescriptorDefinitions>
          <securityDescriptorDefinition name="APPID_SERVICE_ALL_ACCESS" sddl="O:BAG:SYD:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;LS)(A;CI;GA;;;S-1-5-80-2078495744-2416903469-4072184685-3943858305-976987417)" operationHint="replace" />
          <securityDescriptorDefinition name="APPID_SERVICE_ALL_ACCESS_AND_BU_READ_ACCESS" sddl="O:BAG:SYD:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;LS)(A;CI;GA;;;S-1-5-80-2078495744-2416903469-4072184685-3943858305-976987417)(A;CI;GR;;;S-1-15-2-1)" operationHint="replace" />
          <securityDescriptorDefinition name="APPID_SERVICE_ALL_ACCESS_DIRECTORY" sddl="D:AI(A;CIOI;GA;;;LS)" operationHint="replace" />
          <securityDescriptorDefinition name="WRP_FILE_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;;FA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GRGX;;;BA)(A;;GRGX;;;SY)(A;;GRGX;;;BU)(A;;GRGX;;;S-1-15-2-1)S:(AU;FASA;0x000D0116;;;WD)" operationHint="replace" description="Default SDDL for Windows Resource Protected file" />
          <securityDescriptorDefinition name="WRP_REGKEY_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;CI;GR;;;SY)(A;CI;GR;;;BA)(A;CI;GR;;;BU)(A;CI;GR;;;S-1-15-2-1)" operationHint="replace" />
        </securityDescriptorDefinitions>
      </accessControl>
    </security>
  </trustInfo>
  <migration settingsVersion="1">
    <supportedComponents>
      <supportedComponent>
        <assemblyIdentity name="_" version="1.0.0.0" />
        <supportedComponentIdentity xmlns="urn:schemas-microsoft-com:asm.v3" language="neutral" name="Microsoft-Windows-AppIDCore" processorArchitecture="*" settingsVersionRange="1" />
      </supportedComponent>
    </supportedComponents>
    <machineSpecific xmlns="urn:schemas-microsoft-com:asm.v3">
      <migXml xmlns="">
        <environment>
          <variable name="AppLockerDir">
            <text>%windir%\system32\AppLocker</text>
          </variable>
        </environment>
        <rules context="System">
          <include>
            <objectSet>
              <pattern type="File">%AppLockerDir%\* [*]</pattern>
              <pattern type="Registry">HKLM\System\CurrentControlSet\Control\AppID\Configuration\EDP\* [*]</pattern>
              <pattern type="Registry">HKLM\System\CurrentControlSet\Services\appid\ [Start]</pattern>
            </objectSet>
          </include>
          <exclude>
            <objectSet>
              <pattern type="File">%AppLockerDir% [AppCache.dat]</pattern>
            </objectSet>
          </exclude>
        </rules>
      </migXml>
    </machineSpecific>
  </migration>
  <taskScheduler xmlns="urn:schemas-microsoft-com:asm.v3">
    <Task xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
      <RegistrationInfo>
        <Date>2015-02-09T10:54:13.9629482</Date>
        <Author>$(@%SystemRoot%\system32\ApplockerCsp.dll,-100)</Author>
        <Source>$(@%SystemRoot%\system32\ApplockerCsp.dll,-101)</Source>
        <Description>$(@%SystemRoot%\system32\ApplockerCsp.dll,-102)</Description>
        <URI>Microsoft\Windows\AppID\EDP Policy Manager</URI>
        <SecurityDescriptor>D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FA;;;S-1-5-87-2978287140-3787137133-1749738600-1988163579-2060695581)</SecurityDescriptor>
      </RegistrationInfo>
      <Triggers>
        <WnfStateChangeTrigger>
          <StateName>7588bca328009213</StateName>
        </WnfStateChangeTrigger>
        <WnfStateChangeTrigger>
          <StateName>75e0bca328009213</StateName>
        </WnfStateChangeTrigger>
      </Triggers>
      <Principals>
        <Principal id="LocalService">
          <UserId>S-1-5-19</UserId>
        </Principal>
      </Principals>
      <Settings>
        <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>
        <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>
        <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>
        <AllowHardTerminate>false</AllowHardTerminate>
        <StartWhenAvailable>false</StartWhenAvailable>
        <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>
        <IdleSettings>
          <StopOnIdleEnd>true</StopOnIdleEnd>
          <RestartOnIdle>false</RestartOnIdle>
        </IdleSettings>
        <AllowStartOnDemand>true</AllowStartOnDemand>
        <Enabled>true</Enabled>
        <Hidden>false</Hidden>
        <RunOnlyIfIdle>false</RunOnlyIfIdle>
        <DisallowStartOnRemoteAppSession>false</DisallowStartOnRemoteAppSession>
        <UseUnifiedSchedulingEngine>true</UseUnifiedSchedulingEngine>
        <WakeToRun>false</WakeToRun>
        <ExecutionTimeLimit>PT0S</ExecutionTimeLimit>
        <Priority>7</Priority>
      </Settings>
      <Actions Context="LocalService">
        <ComHandler>
          <ClassId>{deca92e0-af85-439e-9204-86679978da08}</ClassId>
          <Data>EdpPolicyManager</Data>
        </ComHandler>
      </Actions>
    </Task>
  </taskScheduler>
</assembly>