Key features

Prev Next

Application Control protects your organization against malware attacks before they occur by proactively controlling the applications that run on your devices. Change Control blocks change activities in server environments to prevent security breaches and data loss, and lowers the impact of outages.

Dynamic allow listing

You can manage your allow list in a secure and dynamic way. IT administrators don't need to manually maintain lists of approved applications. Application Control groups executables (binaries, libraries, and drivers) across your company.

You can easily search for useful information such as:

  • Applications added this week

  • Uncertified binaries

  • Systems running outdated versions

  • Files with unknown reputations (in a ePO - On-prem managed environment only)

Protection against threats

Application Control extends coverage to executable files, libraries, drivers, Java applications, ActiveX controls, and scripts for greater control over application components. It enforces control on connected or disconnected servers, virtual machines, endpoints, and fixed devices, such as kiosks and point-of-sale (POS) terminals. It also locks down protected endpoints against threats and unwanted changes, with no file system scanning or other periodic activity that might impact system performance.

Advanced memory protection

Application Control offers multiple memory-protection techniques to prevent zero-day attacks. Memory-protection techniques provide extra protection over the protection from native Windows features or signature-based buffer overflow protection products. These techniques also prevent allowed applications from being exploited by memory buffer overflow attacks on Windows 32-bit and 64-bit systems.

Knowledge acquisition

You can switch to Observe mode to discover policies for dynamic desktop environments without enforcing a allow list lockdown. This mode helps you deploy the software in pre-production environments without affecting the operation of existing applications.

Note

This feature is available only in a ePO - On-prem managed environment.

Reputation-based execution

Application Control integrates with a reputation source to receive reputation information for files and certificates. Based on the reputation received from one of these sources, Application Control allows or bans the execution and software installation.

Note

This feature is available only in a ePO - On-prem managed environment.

Centralized management

Application Control integrates with ePO - On-prem software for consolidated and centralized management, and a global view of enterprise security from a single console.

Note

This feature is available only in a ePO - On-prem managed environment.

Write protection

Use write protection rules to prevent users from creating and changing files, directories, and registry keys. Write-protecting a file makes it read-only.

Read protection

Read protection rules prevent users from reading the content of specified files, directories, and volumes. If a directory or volume is read-protected, all files in that directory or volume are also read-protected. Subdirectories inherit read protection rules.

Real-time monitoring

Change Control monitors file and registry changes in real time, eliminating need for multiple scans on endpoints to identify change violations.

Content change tracking

Change Control tracks content and attribute changes for files and includes special alerting mechanisms to instantly notify you of critical changes.