Kaspersky Security 11.x for Windows Server

Adding an Applications Launch Control rule

June 10, 2022

ID 178908

To add an Applications Launch Control rule:

  1. Open the Applications Launch Control rules window.
  2. Click the Add button.
  3. In the context menu of the button, select Add one rule.

    The Rule settings window opens.

  4. Specify the following settings:
    1. In the Name field, enter the name of the rule.
    2. In the Type drop-down list, select the rule type:
      • Allowing if you want the rule to allow launch of applications in accordance with the criteria specified in the rule settings.
      • Denying if you want the rule to block launch of applications in accordance with the criteria specified in the rule settings.
    3. In the Scope drop-down list, select the type of files whose execution will be controlled by the rule:
      • Executable files if you want the rule to control launch of executable files.
      • Scripts and MSI packages if you want the rule to control launch of scripts and MSI packages.
    4. In the User or user group field, specify the users who will be allowed or not allowed to start programs based on the type of rule. To do this, perform the following actions:
      1. Click the Browse button.
      2. The standard Microsoft Windows Select user or groups window opens.
      3. Specify the list of users and/or user groups.
      4. Click OK.
    5. If you want to take the values of the rule-triggering criteria listed in the Rule triggering criterion section from a specific file:
      1. Click the Set rule triggering criterion from file properties button.

        The standard Microsoft Windows Open window opens.

      2. Select the file.
      3. Click the Open button.

        The criteria values in the file are displayed in the fields in the Rule triggering criterion group box. The criterion for which data are available in the file properties is selected by default.

    6. In the Rule triggering criterion group box, select one of the following options:
      • Digital certificate if you want the rule to control the start of applications launched using files signed with a digital certificate:
        • Select the Use subject check box if you want the rule to control the launch of files signed with a digital certificate only with the specified header.
        • Select the Use thumb check box if you want the rule to only control the launch of files signed with a digital certificate with the specified thumbprint.
      • SHA256 hash if you want the rule to control the start of programs launched using files whose checksum matches the one specified.
      • Path to file if you want the rule to control the start of programs launched using files located at the specified path.

        Kaspersky Security for Windows Server does not recognize paths that contain slashes ("/"). Use backslash ("\") to enter the path correctly.

        When specifying the objects, you can use file masks (via ? and * characters) and the following types of environment variables: %WINDIR%, %SYSTEM32%, %OSDRIVE%, %PROGRAMFILES%.

    7. If you want to add rule exclusions:
      1. In the Exclusions from rule section, click the Add button.

        The Exclusion from rule window opens.

      2. In the Name field, enter the name of the exclusion.
      3. Specify the settings for exclusion of application files from the Applications Launch Control rule. You can fill out the settings fields from the file properties by clicking the Set exclusion based on file properties button.
        • Digital certificate
        • Use subject
        • Use thumb
        • SHA256 hash
        • Path to file
      4. Click OK.
      5. If necessary, repeat steps (i)-(iv) to add additional exclusions.
  5. Click OK in the Rule settings window.

The created rule is displayed in the list in the Applications Launch Control rules window.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.