It is either AppLocker or WDAC (windows defender application control). These are built-in features that allow administrators to define policies what applications are permitted in your environment. Applocker, for example, has its own event log: Application and Services Logs\Microsoft\Windows\Applocker
They are not enabled by default. You have to enable eventlogs and then it will be filled with the history of permitted and blocked applications.