What is inventory

Prev Next

Inventory is the allow list created during the initial scan called Solidification.

Inventory information is available on the ePO - SaaS console for endpoints. It is updated at regular intervals based on changes made at the endpoints.

Any change to an endpoint's inventory, triggers inventory information to be pushed to the ePO - SaaS server after the agent-server communication interval. This keeps the inventory information about the ePO - SaaS server updated with changes to inventory at the endpoints. Also, this avoids the need to manually fetch inventory for an endpoint to get the updated inventory.

These changes on an endpoint cause corresponding changes to the inventory information about the ePO - SaaS server:

  • Addition of a file

  • Modification of an existing file

  • Rename of a file

  • Deletion of a file

  • Solidification or Unsolidification of a file

Path of solidified files:

  • "<Drive>:Solidcore\Scinv" - Windows

Note

The solidified file is encrypted and can only be decrypted with a special tool from Application Control Engineering. This tool is also version-specific and not available for public use.

What is solidification?

Solidification is the art of creating allow list for protection.

Allow list is created during installation by scanning systems for applications, libraries, drivers, and scripts. If a file is solidified, it is allowed to run but is protected from any modifications to be made to it. Allow listing basics is represented as below:

  • Application tries to launch. It can be an executable or operating system component.

  • Application Control verifies the binary code from allow list.

  • Application does not start, if its binaries are not available on allow list.

GUID-4713C2E3-AE10-4B09-BBB7-2951BA9DFAD7-low.png