AC Overview
On the AC overview, you can check the list of executable
files detected or blocked by the application control function for 30 days,
and set whether to allow or not.
Note
This function is for reacting to files are blocked because
they do not exist in the local inventory. Files blocked from execution
are not displayed in the AC overview.
- First filter the list of application controls
on a file by type (All, File Name, File Hash, Agent IP or Computer
Name) and the keyword.
- Click on the Search
icon.
- From the list of application controls, select
a file to take action.
- Click Take
Action and choose the action to take.
- Allow: Click to allow the execution of the
file. Upon click, the file will no longer be visible from the list
and your choice will be saved in the inventory of the detecting agent.
- Hide: Click to hide the file from the list.
Upon click, the file will be hidden from the list for 30 days, after
which it will be automatically visible again.
- Auto-Enable: Click to automatically enable
the execution of the file. Upon click, the hash value will be saved
in the inventory of the detecting agent. Click Auto-Enabled
List to see and edit the list of enabled files.
Note
When you Auto-Enable a file execution, all files with the
same hash value will be enabled. However, any files in a different location
will be blocked upon initial detection even if it has the same hash value.
- Auto-Enabled List: You can check the list of
auto-enabled files in Take Action. You can delete from the Auto-Enabled
List by clicking Delete.
Upon deleting Auto-Enabled List, all files with the same hash value
will no longer be automatically enabled. However, note that the file
will not be deleted from the detected agent's inventory policy.
- Status: The execution control status of the
file. Distinguishes and displays as Block
(Lock down mode) and Detect (Simulation mode).
- File Name: The name of the file.
- File Hash (SHA 256): The hash value (SHA 256)
of the file.
- Supplier: Displays the file supplier information
only for Windows files.
- Signed by: Displays the file signer information
only for Windows files.
- Agent IP: IP address of the agent that detected
the file.
- Computer Name: The name of the agent PC that
detected the file.
- No. of Detections: The number of file detections.
- ASD Reputations: The ASD (AhnLab Smart Defense)
cloud reputation info of the file.
- Detected On: Date when the file was last detected.