Execution Control tab

Prev Next

Use this tab to define additional attribute-based and granular rules for files in your setup.

Based on the type of rules you define, a file is allowed, blocked, or monitored based on attributes provided.

Option definitions

Option

Definition

Add

Opens the Add Execution Control Rule dialog box. Configure these options, as needed.

  • Action — Select one of these options when adding an execution control rule.

    • Based on specified attributes

      • Monitor — Select to define rules to monitor file execution when run with specified attributes.

      • Block — Select to define rules to prevent file execution when run with specified attributes.

      • Allow — Select to define rules to allow file execution when run with specified attributes.

    • Block interactive mode for console-based process — Select to define rules to block interactive mode for console-based processes.

  • Process Name — Specify the process for which to specify the rule.

  • Attributes for the rule — Specify one or more of these attributes to define an attribute-based rule. These fields are available only when you select the Based on specified attributes action.

    • Path — Select the associated checkbox to use path as a context-based attribute for the rule and specify the path for the process. The rule comes into play only when the process is run from the specified path.

    • Command Line Argument — Select the associated checkbox to use command-line argument as a context-based attribute for the rule and specify the argument. The rule comes into play only when the process is run with the specified argument.

    • Parent Process Name — Select the associated checkbox to use parent process as a context-based attribute for the rule and specify the name of the parent process. The rule comes into play only when the process is run by the specified parent process.

    • User Name — Select the associated checkbox to specify user name as a context-based attribute for the rule and enter the user name. The rule comes into play only when the process is run by the specified user.

    • Rule Description — Enter a rule description. Make sure the description is meaningful and aptly describes the rule.

  • OK — Saves the changes made.

  • Cancel — Exits without saving the changes and returns to the Execution Control page.

Edit

Opens the Edit Execution Control Rule dialog box with information for a selected rule. Edit the rule as needed, then click OK.

Remove

Deletes the selected rule.