Review product features

Prev Next

You can review the list of all Application Control features and their status (enabled or disabled) on your system.

Task

Run this command at the command prompt.
sadmin features list

The features list is displayed on the screen.

Note

Starting from the Application Control 6.0.0 release, the features list has been minimized to show only the features that require changes regularly.

Feature Description Default status Supported Operating System
activex It installs and runs ActiveX controls on the protected system. Only the Internet Explorer browser is supported for the ActiveX control installations. Simultaneous installation of ActiveX controls using multiple tabs of Internet Explorer is not supported. Enabled Windows
checksum It compares the checksum of the file to be executed with the checksum stored in the whitelist. Enabled Windows and Linux
deny-read It read-protects the specified components. When this feature is applied on components, they cannot be read. Read protection works only when Application Control is running in Enabled mode. Disabled Windows and Linux
deny-write It write-protects the specified components. When this feature is applied on the components, they are rendered as read-only to protect your data. Enabled Windows and Linux
discover-updaters

It generates a list of potential updaters that can be included in the system.

It tracks all failed attempts made by authorized executable to change protected files or run other executable files. It also generates a list of possible updaters that can be configured on the system to perform an update.

Enabled Windows
enduser-notification

It displays a customized notification message on the system when Application Control prevents an action on the system. This feature is supported only in the Trellix ePO - On-prem-managed configuration.

Enabled Windows
execution-control

It defines attribute-based rules using one or more attributes of a process to allow, block, or monitor the process.

Enabled Windows
integrity This feature:
  • Protects Application Control files and registry keys from unauthorized tampering.
  • Allows the product code to run even when the components are not present in the whitelist.
  • Ensures that all product components are protected.
  • Prevents accidental or malicious removal of components from the whitelist to ensure that the product doesn't become unusable.
  • Is disabled in update mode to facilitate product upgrades.
Enabled Windows and Linux
mp It protects running processes from hijacking attempts. Unauthorized code injected into a running process is trapped, halted, and logged. It also attempts to gain control of the system through buffer overflow and similar exploits are rendered ineffective. Enabled Windows
mp-casp It renders useless code that is running from the non-code area, which happens due to a buffer overflow being exploited on 32-bit Windows platforms. Enabled Windows
mp-vasr

mp-vasr-forced-relocation

It forces relocation of those dynamic-link libraries (DLLs) that have opted out of the Windows native ASLR feature.

Some malware relies on these DLLs always being loaded at the same and known addresses. By relocating such DLLs, these attacks are prevented.

Enabled Windows
network-tracking It tracks files over network directories and blocks the execution of scripts over network directories. By default, this feature is enabled and prevents the execution of scripts over network directories. When this feature is disabled, execution of scripts over network directories is allowed. Also, write-protecting or read-protecting components over a network directory is not effective. Enabled Windows
pkg-ctrl It manages installation and uninstallation of MSI-based and non-MSI-based installers. Enabled Windows
script-auth It prevents the execution of supported script files that are not in the whitelist. Only whitelisted script files are allowed to execute on the system. For example, supported script files such as .bat, .cmd, .vbs (on Windows), and script files with #! (hash exclamation point) for supported local file systems (on Linux) are added to the whitelist and are allowed to run. Enabled Windows and Linux
throttle It controls the flow of data (events, policy discovery requests, and inventory updates) from each system to the Trellix ePO - On-prem server.

Note

This feature is available only in a Trellix ePO - On-prem managed environment.

Enabled Windows