13.2. Application Rules

Go to the Applications tab in the Behavior Blocking section to view and edit rules for startup and change of particular applications.

Behavior Blocking — Application rules

Figure 13.2. Behavior Blocking — Application rules

These rules are based on interaction with user when an unknown application is started. Rules cannot be created by hand, they can only be edited or removed.

An action that firewall will take after startup (Starting), after the executable file is changed (Modifying) and when another application is run by this application (Launching others) can be set for each application. Actions can be defined:

  1. right from the menu of applications — click on an action to switch between the following actions: permit, deny and ask

  2. right-click on an action and select an action from the context menu

    Behavior Blocking — application rules — action selection

    Figure 13.3. Behavior Blocking — application rules — action selection

  3. in the dialog for rule modification. Use the Edit button or the Edit option in the context menu to open the dialog.

    Behavior Blocking — Editing of application rule

    Figure 13.4. Behavior Blocking — Editing of application rule

    • In the dialog header, description, icon and full path to the application's executable file is provided.

    • Use the Behavior Blocking settings entry to enable setting actions for the described situations.

    • Check or uncheck the Log to system log option to enable/disable log activity for the application (startup, change of the executable file or running another application by this application)

    • Check or uncheck the Show alert to user option to enable/disable the Alert dialog (see chapter 5.5. Alert Dialog Window (alerts on events)) for cases when the application is activated.