Policy -> Application Policy

In today’s digital landscape, managing applications within a corporate or personal network is essential for security, productivity, and compliance. Our Application Policy LAN feature, part of the EDR LAN solution, simplifies this process with a structured approach, allowing users to control which applications can be installed and run on their machines through a dual-mode system. Beyond simple allow/block decisions, the solution gives administrators the ability to allow applications based on their digital signature certificates, MD5, SHA256, metadata, file path, and pre-defined security categories, and to enforce user-based policies so that controls can be tailored to individual users rather than applied uniformly across all machines.

Application control is implemented through two distinct modes.

1. Allow All Except Blocklist

This mode provides flexibility by allowing all applications by default, except those explicitly blocked by users or administrators. It includes:

  • Blocked Patterns: Offers granular control by allowing applications to be blocked based on different criteria such as application name, path location, internal name, company name, MD5 or SHA256 hash, and digital signature certificate.

    Figure 1: Allow All Except Block List – Blocked Patterns (File Path, Company Name, Internal Name, Product Name)

    • Block App Category List: Enables category-based blocking using pre-defined security categories, ensuring entire groups of applications are restricted when needed.

      Figure 2: Allow All Except Block List – Blocked App Category List (45 pre-defined security categories)

      2. Block All Except Allowlist

      This mode is stricter—it blocks all applications by default unless explicitly whitelisted. It includes:

      1. Blocked Patterns: Similar to the first mode, this feature allows further restrictions on applications that might have bypassed initial controls.
      2. App Whitelist: Allows individual applications to be whitelisted by specifying the full application name, path, MD5 or SHA256 hash, metadata, or digital signature certificate.

      Figure 3: Block All Except Allow List – App Whitelist (Exe Name, Exe Path, Import)

      3. Allow App Category List:

      Offers the ability to whitelist applications based on pre-defined security categories, ensuring essential software remains accessible.

        Figure 4: Block All Except Allow List – Allow App Category List

        Both modes support user-based policies, allowing administrators to apply different application control rules to specific users or user groups according to their roles and requirements.

        Hash-Based Application Control (IOC Hash)

        In addition to pattern and category controls, the EDR LAN solution allows administrators to allow or block applications based on file hashes. Supported hash formats include MD5, SHA-1, and SHA-256, enabling precise identification of malicious applications or malware regardless of file name or location.

        Figure 5: IOC Hash – Imported Hash list supporting MD5, SHA-1, and SHA-256 formats

        Detailed reports provide visibility into every blocked execution, including the computer name, IP address, application path, blocked type, hash value, hash type, and applied policy—supporting continuous monitoring for the installation of unauthorized software.

        Figure 6: IOC Hash – Reports showing blocked applications with hash, path, and endpoint details

        Remote Management Capabilities

        Beyond application control, the EDR LAN solution includes features to manage computers remotely across the network. Administrators can perform remote installation of third-party software, manage the complete hardware and software inventory of all connected assets, and continuously monitor endpoints for the installation of unauthorized software—giving IT teams centralized oversight and control without needing physical access to each machine.

        Hardware & Software Inventory Management

        The Software Management console gives administrators a centralized view of every connected asset across the network. For each endpoint it displays the computer name, client IP address, license key number, and the last keep-alive status, making it easy to track the inventory of all managed machines and monitor which software is installed on each one.

        Figure 7: Software Management – Centralized inventory of connected assets with computer name, IP, key, and status

        Remote Installation of Third-Party Software

        Through the built-in Software Library, administrators can remotely deploy third-party software to endpoints. The library provides a comprehensive catalogue of applications—including software name, version, executable, platform, vendor, architecture, and installation/uninstall switches—allowing one-click remote installation. This standardizes deployment, reduces manual effort, and ensures only approved, authorized software is installed across the organization, helping monitor and prevent the installation of unauthorized software.

        Figure 8: Software Library – Catalogue of deployable third-party software with version, platform, and install switches

        Why Application Control Matters?

        In an era where cyber threats are becoming more advanced, unrestricted access to applications can pose serious risks. Malware, unauthorized software, or even productivity-draining applications can enter systems without proper oversight. Here’s why Application Policy LAN can be a lifesaver:

        • Enhanced Security: Prevents malicious applications from entering the network and strengthens endpoint security.
        • Optimized Productivity: Blocks unnecessary or distracting software, keeping employees focused on work-related tasks.
        • Compliance-Friendly: Organizations can enforce regulatory policies by controlling which applications users can install.
        • Granular Identification: Multiple identification methods—digital signatures, MD5, SHA256, metadata, file path, and security categories—ensure precise and reliable application control.
        • Centralized Remote Control: Remote software installation, asset inventory management, and unauthorized software monitoring reduce administrative overhead and improve response times.