Contents
About Application Control
The Application Control component monitors users' attempts to start applications and regulates the startup of applications by using Application Control rules.
Application Control component is available for Kaspersky Endpoint Security for Windows and for Kaspersky Security for Virtualization Light Agent. All the instructions in this section describe configuration of Application Control for Kaspersky Endpoint Security for Windows.
Startup of applications whose settings do not match any of the Application Control rules is regulated by the selected operating mode of the component:
- Denylist. The mode is used if you want to allow the startup of all applications except the applications specified in block rules. This mode is selected by default.
- Allowlist. The mode is used if you want to block the startup of all applications except the applications specified in allow rules.
The Application Control rules are implemented through application categories. You create application categories defining specific criteria. In Kaspersky Security Center there are three types of application categories:
- Category with content added manually. You define conditions, for example, file metadata, file hashcode, file certificate, KL category, file path, to include executable files in the category.
- Category that includes executable files from selected devices. You specify a device whose executable files are automatically included in the category.
- Category that includes executable files from selected folder. You specify a folder from which executable files are automatically included in the category.
For detailed information about Application Control, refer to Kaspersky Endpoint Security for Windows Online Help and to the Kaspersky Security for Virtualization Light Agent.