Kaspersky Security 11.x for Windows Server

Managing Applications Launch Control via the Web Plug-in

June 10, 2022

ID 192821

To configure Applications Launch Control tasks via the Web Plug-in:

  1. In the main window of the Web Console, select DevicesPolicies & profiles.
  2. Click the policy name you want to configure.
  3. In the <Policy name> window that opens select the Application settings tab.
  4. Select the Local activity control section.
  5. Click Settings in the Applications Launch Control subsection.
  6. Configure the settings described in the table below.

    Applications Launch Control task settings

    Setting

    Description

    Task mode

    In this drop-down list, you can select the Applications Launch Control task’s mode:

    • Active. Kaspersky Security for Windows Server uses the specified rules to control the launch of any application.
    • Statistics only. Kaspersky Security for Windows Server does not use the specified rules to control application launches. Instead, it simply records information about launch events in the task log. All applications are allowed to start. You can use this mode to generate a list of Applications Launch Control rules based on the information about denied application launches recorded in the task log.

    By default, the Applications Launch Control task runs in Statistics only mode.

    Repeat action taken for the first file launch on all the subsequent launches for this file

    The check box enables or disables launch control for the second and subsequent attempts to start applications based on the event information stored in the cache.

    If the check box is selected, Kaspersky Security for Windows Server allows or denies subsequent launches of an application based on the task’s conclusion regarding the first launch of the application. For example, if the first application launch was allowed by the rules, information about this decision will be stored in the cache, and the second and all subsequent launches will also be allowed without rechecking.

    If the check box is cleared, Kaspersky Security for Windows Server analyzes an application every time a launch is attempted.

    The check box is selected by default.

    Deny the command interpreters launch with no command to execute

    If the check box is selected, Kaspersky Security for Windows Server denies the launch of command line interpreters even if launching interpreters is allowed. A command interpreter can only be launched with no command if both of the following conditions are met:

    • Launch of the command line interpreter is allowed.
    • The command to be executed is allowed.

    If the check box is cleared, Kaspersky Security for Windows Server only considers allowing rules when launching a command line interpreter. The launch is denied if no allowing rule applies or the executable process is not trusted by KSN. If an allowing rule applies or the process is trusted by KSN, a command line interpreter can be launched with or without a command to execute.

    Kaspersky Security for Windows Server recognizes the following command line interpreters:

    • cmd.exe
    • powershell.exe
    • python.exe
    • perl.exe

    The check box is cleared by default.

    Apply rules to executable files

    The check box either enables or disables launch control of executable files.

    If this check box is selected, Kaspersky Security for Windows Server allows or blocks start of executable files using the specified rules whose settings specify Executable files as the scope.

    If the check box is cleared, Kaspersky Security for Windows Server does not control start of executable files using the specified rules. Startup of executable files is allowed.

    The check box is selected by default.

    Monitor loading of DLL modules

    The check box either enables or disables control of loading of DLL modules.

    If this check box is selected, Kaspersky Security for Windows Server allows or blocks loading of DLL modules using the specified rules whose settings specify Executable files as the scope.

    If this check box is cleared, Kaspersky Security for Windows Server does not control loading of DLL modules using the specified rules. Loading of DLL modules is allowed.

    The check box is active if the Apply rules to executable files check box is selected.

    The check box is cleared by default.

    Apply rules to scripts and MSI packages

    The check box either enables or disables launch of scripts and MSI packages.

    If this check box is selected, Kaspersky Security for Windows Server allows or blocks start of scripts and MSI packages using the specified rules whose settings specify Scripts and MSI packages as the scope.

    If the check box is cleared, Kaspersky Security for Windows Server does not control start of scripts and MSI packages using specified rules. Start of scripts and MSI packages is allowed.

    The check box is selected by default.

    Deny applications untrusted by KSN

    The check box either enables or disables Applications Launch Control according to application reputation data in KSN.

    If this check box is selected, Kaspersky Security for Windows Server blocks any application from running if it is not trusted in KSN. Applications Launch Control allowing rules that apply to applications not trusted in KSN will not be triggered. Selecting the check box provides additional protection from malware.

    If the check box is cleared, Kaspersky Security for Windows Server does not consider the reputation of applications not trusted in KSN and allows or blocks start in accordance with the rules that apply to such applications.

    The check box is cleared by default.

    Allow applications trusted by KSN

    The check box either enables or disables Applications Launch Control according to application reputation data in KSN.

    If this check box is selected, Kaspersky Security for Windows Server allows applications to run if they are trusted in KSN. Denying application launch control rules that apply to KSN-trusted applications have higher priority: if an application is trusted by KSN services, the application launch will be denied.

    If the check box is cleared, Kaspersky Security for Windows Server does not consider the reputation of KSN-trusted applications and allows or denies launch in accordance with rules that apply to such applications.

    The check box is cleared by default.

    Users and / or user groups allowed to run applications trusted by KSN

    If the Allow applications trusted by KSN check box is selected, here you can specify users and user groups allowed to start applications that are trusted by KSN.

    By default, the following users are specified: Everyone and NT AUTHORITY\SYSTEM.

    Rules

    Configure allowing or denying rules for the Application Launch Control task.

    Software Distribution Control

    You can add trusted distribution packages.

    Task management

    You can configure settings to start the task on a schedule.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.