Application Control creates a whitelist of all authorized executable files and blocks the execution of any program that isn't whitelisted.
Change Control monitors and prevents changes to the file system and it write-protects and read-protects critical files from unauthorized tampering.
The whitelist details authorized files and determines trusted or known files. In Enabled mode, only files that are present in the whitelist are allowed to run. All files in the whitelist are protected and can't be changed or deleted.
Application Control stores the whitelist for each drive or volume at the following location:
Application Control and Change Control > Application and Change Control 6.x > Trellix Application and Change Control 6.4.x - Linux Product Guide > Product overview
Application Control and Change Control > Application and Change Control 6.x > Trellix Application and Change Control 6.6.x - Linux Product Guide > Product overview
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Product overview