Key features

Prev Next

Application Control protects your organization against malware attacks before they occur by proactively controlling the applications that run on your devices.

Dynamic allow listing

You can manage your allow list in a secure and dynamic way. IT administrators don't need to manually maintain lists of approved applications. Application Control groups executables (binaries, libraries, and drivers) across your company.

You can easily search for useful information such as:

  • Applications added this week

  • Uncertified binaries

  • Systems running outdated versions

  • Files with unknown reputations

Protection against threats

Application Control extends coverage to executable files, libraries, drivers, Java applications, and scripts for greater control over application components. It enforces control on connected or disconnected servers, virtual machines, endpoints, and fixed devices, such as kiosks and point-of-sale (POS) terminals. It also locks down protected endpoints against threats and unwanted changes, with no file system scanning or other periodic activity that might impact system performance.

Advanced memory protection

Application Control offers multiple memory-protection techniques to prevent zero-day attacks. Memory-protection techniques provide extra protection over the protection from native Windows features or signature-based buffer overflow protection products. These techniques also prevent allowed applications from being exploited by memory buffer overflow attacks on Windows 32-bit and 64-bit systems.

Knowledge acquisition

You can switch to Observe mode to discover policies for dynamic desktop environments without enforcing an allow list lockdown. This mode helps you deploy the software in pre-production environments without affecting the operation of existing applications.

Reputation-based execution

Application Control integrates with a reputation source to receive reputation information for files and certificates. Based on the reputation received from one of these sources, Application Control allows or bans the execution and software installation.

Centralized management

Application Control integrates with ePO - SaaS software for consolidated and centralized management, and a global view of enterprise security from a single console.