How Application Control works in a managed environment

Prev Next

Application Control creates a allow list of all authorized executable files. When you attempt to run an executable file that isn't allowed, Application Control checks the reputation of the file and allows or blocks its execution.

  1. A user or application tries to execute a file on a managed endpoint where Application Control and Trellix Agent are installed.

  2. Application Control checks the reputation of the file and allows or blocks its execution.

  3. Application Control communicates with the Trellix Threat Intelligence Exchange (TIE) servers to receive reputation information for the file and any associated certificates. Based on this information, Application Control allows or blocks the file execution.

  4. If the TIE server is unavailable, Application Control communicates with the Global Threat Intelligence server to fetch the reputation of the file.

  5. Trellix Data Exchange Layer provides the framework for communication between Application Control and TIE or Trellix GTI, so products can share threat information.

  6. The administrator manages all endpoints, deploys policies, creates rules, adds certificates, manages the inventory, monitors activities, and approves requests.

  7. Information about the attempt to run the application is sent to the ePO - On-prem server, where it appears in a dashboard, report, or log.

GUID-642CA9A5-6942-4A91-9D74-8098C25A950F-low.png