Select the Prevention section in the program web interface window.
The prevention rule table opens
Click the Add button.
The prevention rule creation window opens.
Specify the following parameters:
State is the state of the prevention rule:
If you want to enable the prevention rule, set the toggle switch to On.
If you want to disable the prevention rule, set the toggle switch to Off.
MD5/SHA256—MD5- or SHA256 hash of the file or data stream that you want to prevent from starting.
Data streams of the NTFS file system (alternate data streams) are intended for additional attributes or information on a file.
Each file in the NTFS file system consists of a set of streams. One of them contains the file contents that we will be able to see by opening the file. The other (alternate) ones are intended for metadata and to ensure, for example, compatibility between the NTFS system and other systems, such as the old Macintosh file system known as Hierarchical File System (HFS). Streams can be created, deleted, individually saved, renamed, and can even be run as a process.
Alternate streams can be used by hackers for concealed transmission or receipt of data from a computer.
Name is the name of the prevention rule.
If you want the program to show a prevention rule triggering notification to the user of the computer on which the prevention is applied, select the Notify user about the task execution check box.
Prevent on is the prevention rule scope:
If you want to apply the prevention rule on all hosts of all servers, select All hosts.
If you want to apply the prevention rule on selected servers, select the Specified servers option and on the right of the Servers parameter name select the check boxes next to the names of the servers on which you want to apply the prevention rule.
Operation mode in which the program can be used to protect the infrastructure of several organizations simultaneously.
If you want to apply the prevention rule on selected hosts, select the Specified hosts option and list these hosts in the Hosts field.
Click the Add button.
The file startup prevention will be created.
If you selected the Notify user about the task execution check box and there is an attempt to start a file prevented from running, the user will be notified that a startup prevention rule was triggered by this file.