Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JonnyRabinowitz
Employee
Employee

Application Control Functionality - Custom rules / application whitelisting

Within Harmony Endpoint there are two alternative mechanisms for application control

  • App Rules: Configuration based on the Applications that were uploaded within the Appscan XML file
  • Custom Rules: Flexible sets of custom rules that are defined by the administrator

In recent Windows endpoint releases the following enhancements were made for Custom Rules

  • Wildcards can be specified in rules. For example can define all versions of a specific application rather than multiple rules each based on a specific hash
  • Rules can be defined based on values in certificates. For example all application signed by certificate with specific name
  • Application whitelisting. Allows the default action to be defined  “Terminate”. This capability effectively enables “Application Whitelisting” where can specify all the applications that are allowed to run and then ensure that all others are terminated. Note that processes associated with O/S and Harmony Endpoint are implicitly defined and allowed to run and do not need to be defined in the configuration

Application whitelisting is available in E87.60 as EA (Early Availability) functionality. Moving forward custom rules are recommended for customers new to application control and can also be assessed for customers with existing configuration using app rules to replace these definitions

If there is anyone who wants to assess the full capabilities of the custom rules, and also use for whitelisting with latest enhancements, please reach out to me directly and can assess enabling the EA functionality

Also feel free to contact me if looking for additional details on application control

0 Kudos
6 Replies
MARCO-ROCHA
Participant

Screenshot_1.pngI need help blocking Opera and Opera GX in my environment, but it must be done in a way that blocks all versions — past, current, and future — without depending on version numbers or file hashes.

I want a method that completely prevents the browser from running, regardless of updates or new releases.

Marco Rocha
0 Kudos
lluner
Advisor

@JonnyRabinowitz 

That's right, I've had problems with different versions of an application before. Even using AppScan, it only retrieves the specific version's hash. How is it possible to block an application, for example, by tracking the executable path?

0 Kudos
MARCO-ROCHA
Participant

Screenshot_2.png

I managed to solve it this way. If anyone comes across this topic with the same issue, the configuration done like this will block the app and all older and updated versions.

 

 

 

Marco Rocha
lluner
Advisor

@MARCO-ROCHA 

It didn't work, as you described.

AP3.pngAP2.pngAP.png

0 Kudos
MARCO-ROCHA
Participant

The block is for usage — in my case, it prevents the person from browsing the internet using the Opera browser. This happens because of the ‘BLOCK’ option. Try using ‘TERMINATE’ in your case; it might solve the issue.

Marco Rocha
0 Kudos
lluner
Advisor

It didn't work with terminate.

san4.png

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events