So I have been rolling AppLocker out to more people with WEM. However parsing the WEM logs to get false positives to add to my config is a PITA. So with the help of CoPilot AI (not sponsored) I created a powershell script that can read WEM reports for much easier review. Test it out, and let me know what you think.
https://www.jeffriechers.com/wiki/wem-applocker-report-parsing/