Application Control and Change Control can operate in four different modes. Each mode is different in principle and usage.
Enabled mode in an unmanaged environment
This mode indicates that only allow listed applications and files are allowed to run. Execution of unauthorized software, such as a virus or spyware, is prevented. In Enabled mode, Application Control protects files in the allow list from unauthorized change. After the initial allow list is created, switch to Enabled mode which makes sure that no unauthorized changes are allowed.
Enabled mode in a managed environment
This mode indicates that Application Control is running and protection is enabled. Enabled mode supports reputation-based execution. When you execute a file, Application Control fetches its reputation and that of all certificates associated with the file to determine whether to allow or ban the file execution. Application Control works with TIE Server and Trellix GTI to fetch reputation information for a file.
These are the available reputation values:
Trusted files— If the reputation is trusted, the file is allowed to run, unless it is blocked by a predefined ban rule. No observation or event is generated.
Malicious files— If the reputation is malicious, the file isn't allowed to run. An event is generated and displayed on the Solidcore Events page. You can configure the reputation values that are banned in your endpoints. You can ban Known Malicious, Most Likely Malicious, Might be Malicious files, or all malicious files.
Unknown— If the reputation is unknown, reputation values aren't used to determine execution. Instead, Application Control performs other checks to determine whether to allow or block the file.
In Enabled mode, Application Control:
Allows only trusted (based on reputation) or authorized (based on rules) applications and installers to run on servers and endpoints.
Protects against memory-based attacks and application tampering.
Regardless of the file's reputation, if a ban by name, SHA-1, or SHA-256 rule exists for an executable file, its execution is banned. No corresponding observation is generated. A corresponding event is generated and displayed on the Solidcore Events page.
Observe mode
This mode indicates that Application Control is running but it only monitors and logs observations. The application doesn't prevent any execution or changes made to the endpoints. Instead, it monitors execution activities and compares them with the local inventory and predefined rules.
Observe mode also supports reputation-based execution. When you execute a file, Application Control fetches its reputation and that of all certificates associated with the file to determine whether to allow or ban the file execution.
An observation is logged in Observe mode for actions that Application Control allows but can normally block in Enabled mode. These observations help refine policies, and the corresponding files are not automatically added to the allow list.
Important
This mode is available only with Application Control and in a ePO - On-prem managed environment.
Update mode
This mode indicates that protection is effective but changes are allowed on protected endpoints. When you perform software updates in Update mode, Application Control tracks and records each change. Also, it dynamically updates the allow list to make sure that the new binaries and files are authorized to run when the system returns to Enabled mode. In Update mode, all tracked changes are added to the allow list. If you delete any software or program files from the system, their names are also removed from the allow list.
In a managed environment, Update mode supports reputation-based execution. When you execute a file at an endpoint, the software fetches the file's reputation and the reputation of all associated certificates to determine whether to allow or ban the file execution.
Tip
Best practice: Use Update mode only for installing minor software updates. For example, define an interval to allow the IT team to complete maintenance tasks, such as installing patches or upgrading software.
Disabled mode
This mode indicates that the software isn't running on your system. Although the application is installed, its features are disabled. After installation, the application appears in Disabled mode by default. You can then switch to Observe, Update, or Enabled mode.
Inventory mode
This mode indicates that protection is not effective but changes are allowed on endpoints. When you perform software updates in Inventory mode, Application Control tracks and records each change. Also, it dynamically updates the allow list with the new binaries and files. In this mode, all tracked changes are added to the allow list. If you delete any software or program files from the system, their names are also removed from the allow list. On managed systems, all these changes on the allow list will fetch the Inventory on the ePO, keeping this information updated with all the changes on the endpoint.
Switching between modes
From Observe mode, you can switch to Enabled, Disabled, or Inventory mode.
From Enabled mode, you can switch to Disabled, Update, Observe, or Inventory mode.
From Update mode, you can switch to Enabled, Disabled, or Inventory mode.
From Disabled mode, you can switch to Enabled, Update, Observe, or Inventory mode.
From Inventory mode, you can switch to Disabled, Update, or Observe mode.
.png)