Adding a trigger condition for the Application Control rule

For more convenience when creating Application Control rules, you can create application categories.

It is recommended to create a "Work applications" category that covers the standard set of applications that are used at the company. If different user groups use different sets of applications in their work, a separate application category can be created for each user group.

To create an application category in the Administration Console:

  1. Open the Kaspersky Security Center Administration Console.
  2. In the Administration Console tree, select the Additional → Application management → Application categories folder.
  3. Click the New category button in the workspace.

    The user category creation wizard starts.

  4. Follow the instructions of the user category creation wizard.

Step 1. Selecting the category type

At this step, select one of the following types of application categories:

When creating a category with content added automatically, Kaspersky Security Center performs inventory on files with the following formats: EXE, COM, DLL, SYS, BAT, PS1, CMD, JS, VBS, REG, MSI, MSC, CPL, HTML, HTM, DRV, OCX, and SCR.

Step 2. Entering a user category name

At this step, specify a name for the application category.

Step 3. Configuring the conditions for including applications in a category

This step is available if you selected the Category with content added manually category type.

At this step, in the Add drop-down list, select the conditions for including applications into the category:

Step 4. Configuring the conditions for excluding applications from a category

This step is available if you selected the Category with content added manually category type.

Applications specified at this step are excluded from the category even if these applications were specified at the "Configuring the conditions for including applications in a category" step.

At this step, in the Add drop-down list, select conditions for excluding applications from the category:

Step 5. Settings

This step is available if you selected the Category that includes executable files from selected devices category type.

At this step, click the Add button and specify the computers whose executable files will be added to the application category by Kaspersky Security Center. All executable files from the specified computers presented in the Executable files folder will be added to the application category by Kaspersky Security Center.

At this step, you can also configure the following settings:

Step 6. Repository folder

This step is available if you selected the Category that includes executable files from a specific folder category type.

At this step, specify the folder in which Kaspersky Security Center will search for executable files to automatically add applications to the application category.

At this step, you can also configure the following settings:

Step 7. Creating a custom category

Exit the Wizard.

To add a new trigger condition for an Application Control rule in the application interface:

  1. In the main application window, click the Application settings icon in the form of a gear wheel. button.
  2. In the application settings window, select Security ControlsApplication Control.
  3. Click the Blocked applications or Allowed applications button.

    This opens the list of Application Control rules.

  4. Select the rule for which you want to configure a trigger condition.

    The Application Control rule properties open.

  5. Select the Conditions: N tab or Exclusions: N tab and click the Add button.
  6. Select the trigger conditions for the Application Control rule:
    • Conditions from properties of started applications. In the list of running applications, you can select the applications to which the Application Control rule will be applied. Kaspersky Endpoint Security also lists applications that were previously running on the computer. You need to select the criterion that you want to use to create one or multiple rule trigger conditions: File hash, Certificate, KL category, Metadata or Path to file or folder.
    • Conditions "KL category". A KL category is a list of applications that have shared theme attributes. The list is maintained by Kaspersky experts. For example, the KL category known as "Office applications" includes applications from the Microsoft Office suite, Adobe® Acrobat®, and others.
    • Custom condition. You can select the application file and select one of the rule trigger conditions: File hash, Certificate, Metadata or Path to file or folder.
    • Condition by file drive (removable drive). The Application Control rule is applied only to files that are run on a removable drive.
    • Conditions from properties of files in the specified folder. The Application Control rule is applied only to files in the specified folder. You can also include or exclude files from subfolders. You need to select the criterion that you want to use to create one or multiple rule trigger conditions: File hash, Certificate, KL category, Metadata or Path to file or folder.
  7. Save your changes.

When adding conditions, please take into account the following special considerations for Application Control:

Page top