Define attribute-based rules for file execution

Prev Next

Attribute-based rules provide flexibility to allow or block file execution, as needed.

  1. On the Rule Groups tab, locate your Group Name and under Actions, click Edit.

  2. On the Execution Control tab, click Add.

  3. To define an attribute-based rule for a file, select Based on specified attributes.

  4. Select the type of rule to define: Allow, Block, or Monitor.

  5. Specify the file name.

  6. Specify the attributes to define the rule.

    You can use one or all attributes to define the rule. Available attributes are path, command line, parent process, and user. You can use the AND operator to combine rules based on different attributes.

    1. Select the checkbox associated with the attribute.

    2. Select the operator for the attribute.

    3. Enter the string.

  7. (Optional) Enter the rule description.

  8. Click OK.