Black listed software alerts

I work in an enterprise environment. I'm trying to figure out a way to create a list of blacklisted software and have splunk send an alert to the score card whenever any blacklisted software is installed on a user's host. Any idea of how I can get this done?

