You can identify a list of possible updaters that can be added to a system.
When running in Enabled mode, Application Control protection can prevent a legitimate application from running (if the required rules are not defined). The software tracks all failed attempts made by authorized executable to change protected files or run other executable files. You can review the information of failed attempts to identify update rules to allow legitimate applications to run.
Get a list of components that can be added as updaters:
sadmin diagNote
Review the list to ensure that no restricted programs or programs with generic names, such as /usr/bin/bash, are set as authorized updaters.