Application Control can work with a reputation managing source such as Trellix GTI file reputation service to fetch reputation information of files and certificates.
Based on information fetched from the reputation source, application, and executable files in the inventory are sorted into trusted, malicious, and unknown categories.
Manage the unclassified application in your environment to reduce the number of unknown applications. This list typically includes all unknown applications, and can be considered as greylist for your enterprise. The goal is to minimize risk and achieve 95% classification by removing or reclassifying unknown files and applications. Review and process greylist routinely to keep it to a minimum size.
Run GetClean on endpoints with a high number of unknown files. The GetClean utility submits files for analysis to Trellix Labs where they are verified and classified automatically and correctly.
Reclassify, internally developed, recognized, or trusted (from a reputed vendor or signed by a credible certificate) files that are currently in the unknown list.
For Known Malicious and Might be Malicious files or certificates encountered in your environment, the software generates events that are displayed on the Menu → Reporting → Threat Event Log page. The Bad Binary has been detected in Enterprise automatic response is preconfigured in Application Control but is disabled by default. Make sure that the mail server for your enterprise is configured on the ePO - SaaSconsole. For more information about how to set up an email server, see ePO - SaaS Product Guide.
Review the Solidcore: Inventory dashboard regularly to track and monitor inventory status for your environment.
Designate a base image for your enterprise to create an approved repository of known applications, including internally developed, recognized, or trusted applications. This makes management of desktop systems easier by verifying the corporate applications. Here are high-level steps to follow:
Validate and review all applications on a system.
Run GetClean on the system to classify all unknown applications on the system.
Set the base image on the approved system by using the Mark Trusted option.
Adding all binaries from the trusted system to your policy using Attr (auth by name) or Auth (auth by checksum) is not needed. This could cause performance issues on your clients. Solidification of a system with GTI reputation allows everything known with good reputation to run on your system.