Creating a prevention rule

To create a prevention rule:

  1. Select the Prevention section in the program web interface window.

    This opens the prevention rule table

  2. Click the Add button.

    This opens the prevention rule creation window.

  3. Configure the following settings:
    1. State is the state of the prevention rule:
      • If you want to enable the prevention rule, set the toggle switch to On.
      • If you want to disable the prevention rule, set the toggle switch to Off.
    2. MD5/SHA256—MD5- or SHA256 hash of the file or data stream that you want to prevent from starting.
    3. Name is the name of the prevention rule.
    4. If you want the program to show a prevention rule triggering notification to the user of the computer on which the prevention is applied, select the Notify user about the task execution check box.
    5. Prevent on is the prevention rule scope:
      • If you want to apply the prevention rule on all hosts of all servers, select All hosts.
      • If you want to apply the prevention rule on selected servers, select the Specified servers option and on the right of the Servers parameter name select the check boxes next to the names of the servers on which you want to apply the prevention rule.

        This option is available only when distributed solution and multitenancy mode is enabled.

      • If you want to apply the prevention rule on selected hosts, select the Specified hosts option and list these hosts in the Hosts field.
  4. Click the Add button.

The file startup prevention will be created.

If you selected the Notify user about the task execution check box and there is an attempt to start a file prevented from running, the user will be notified that a startup prevention rule was triggered by this file.

See also

Managing policies (prevention rules)

Viewing the prevention rule table

Viewing a prevention rule

Enabling and disabling a prevention rule

Deleting prevention rules

Filtering prevention rules by name

Filtering prevention rules by type

Filtering prevention rules by file hash

Filtering prevention rules by server name

Clearing a prevention rule filter

Page top