Edit Solidcore page

Prev Next

Edit Solidcore license information for Application Control, Change Control, and Integrity Control. You can also configure generic Application Control settings and settings for other features, such as GTI cloud, inventory, and Observe mode.

Option definitions

Option

Definition

License Information

When you install the Solidcore extension, a default evaluation license for Integrity Control lasting 90 days is provided. You can extend this evaluation license for another 90 days or add a full license. The license key determines the features that are enabled. Any or all features can be enabled and used at the same time.

  • Change Control — Type the Change Control license key downloaded with the product from Trellix download website.

  • Application Control — Type the Application Control license key downloaded with the product from Trellix download website.

  • Integrity Control — Type the Integrity Control license key downloaded with the product from the Trellix download website.

General

  • Generic launcher processes — Specify the critical processes for your environment. Certain processes on the Windows operating system, such as explorer.exe and iexplore.exe, are launcher processes that are vital to the operating system. Although observations are generated for generic launcher processes, no suggestions are provided. Also, when using the Policy Discovery feature, no updater rules are generated for generic launcher processes at the endpoints. When allowed to execute based its reputation, no updater privileges are given to a generic launcher process.

  • Restricted certificate names — Certificates from certain vendors, such as Microsoft, are associated with multiple commonly used applications and should not be used to define rules based on the certificate. This field lists the certificates that are unavailable to the Allow by Certificate Globally option. If the main executable file in a request is signed by one of these certificates, you cannot create rules based on the certificate associated with the file.

  • File paths to ignore while fetching inventory — Specify the files (by specifying the file extension) that you do not want to manage in the inventory. No information for the specified file types is stored in the inventory tables.

  • Generate alert for files with reputation value at and below — Specify the reputation value for event generation. Events are generated for all files with the reputation at and below this value. If needed, you can set up responses to receive a notification for these events.

  • Synchronize reputation information with Trellix GTIServer — Specify whether the Application Control software periodically synchronizes with the Trellix GTI file reputation service to fetch reputation information for files in the inventory.

  • Threshold count at which to initiate throttling and suspend observation generation — Specify the threshold value at which to initiate observation throttling. This option applies to endpoints running version 6.1.2 and later.

  • Allow group administrators to manage Policy Discovery requests for entire System Tree — By default, the non-global administrators have permissions to review and manage requests generated by all systems in their associated group (within My Organization). However, if you are a ePO - On-prem administrator, you can set this option to Yes to provide permissions to all non-global administrators to review and take custom actions on the enterprise-wide requests, if needed.