Table of contents

View and change Application Control software rulesets

Each computer has its own Application Control software ruleset. You can do the following:

If a user reports that Application Control is blocking software that they need to run on a particular computer, you can undo the block rule on that computer. Go to Events & Reports > Application Control Events > Security Events, find the computer, locate the block event, and then click View Rules. In the dialog that appears, you can change the block rule to an allow rule.

View Application Control software rulesets

To view the list of Application Control software rulesets, go to Policies > Common Objects > Rules > Application Control Rules > Software Rulesets.

Application Control software rulesets

To see which rules are part of a ruleset, double-click the ruleset and go to the Rules tab. The Rules tab displays the software files that have rules associated with them and enables you to change allow rules to block, and vice versa. See Change the action of one Application Control rule.

Security Events

Application Control Security Events

Events & Reports > Events > Application Control Events > Security Events displays all unrecognized software that either was run on a computer or was actively blocked from running. You can filter this list by time period and other criteria. For more information, see Application Control events.

For each event (except aggregated events), you can click View rules to change the rule from Allow to Block or vice versa.

The agent versions 10.2 and later include event aggregation logic to reduce the volume of logs when the same event occurs repeatedly. See Interpret aggregated security events.

Change the action for an Application Control rule

If you want to allow a software that you previously blocked (or the opposite), you can edit the action in the rule. If you need to undo the rule so that the software is not recognized by Application Control (in other words, delete the rule, not only change its action), see Delete an individual Application Control rule instead.

  1. Go to Policies > Common Objects > Rules > Application Control Rules > Software Rulesets.
  2. Double-click to select the ruleset that contains the rule that you want to change.
  3. On the dialog that appears, go to the Rules tab.
  4. If you want to focus on software that was blocked (or allowed), then in the menu next to Application Control Rules, select By Action to group similar rules. Alternatively, you can use the search to filter the list.

    Application Control rules actions

    If you want to change the action for a software file, but it has multiple different file names , select By File Name to group related rules.

  5. Find the row for the specific software that you want to allow or block.

  6. In the Action column, change the setting to allow or block, then click OK.

    The next time that the agent connects with Workload Security, the rule is updated and the version number increases.

Delete an individual Application Control rule

If you want to undo a rule that you created, go to Policies > Common Objects > Rules > Application Control Rules > Software Rulesets, double-click the ruleset that contains the rule, go to the Rules tab, select the rule and then click Delete.

Keep in mind the following:

  • When the rules are not needed anymore, you can delete them to reduce the size of the ruleset. This improves performance by reducing RAM and CPU usage.
  • If you delete a rule, Application Control cannot recognize the software anymore. If the software is installed again, it appears again on the Actions tab.
  • If a software update is unstable and you might need to downgrade, keep rules that allow rollback to the previous software version until you have completed testing.
  • To find the oldest rules, go to Policies > Rules > Application Control Rules > Software Rulesets, then click Columns. Select Date/Time (Last Change), click OK, and then click that column's header to sort by date.

Delete an Application Control ruleset

If an Application Control ruleset is not being used anymore (for example, if the computer associated with the ruleset no longer exists), you can delete it.

To delete a ruleset, go to Policies > Rules > Application Control Rules > Software Rulesets, click a ruleset to select it, and click Delete.