Repository navigation
docs: add Application Control extension page - #473
pllesperance-lc wants to merge 2 commits into
Conversation
Document the ext-app-control extension: pre-execution allow/deny by path, signer, signing ID, signer root or SHA-256 on Windows and macOS, with permissive, permissive_sync and enforcing modes. Covers decision order, policy document and rule kinds, examples, staged rollout, hive/CLI configuration, the app_control_policy command, status and degraded flags, and the APP_CONTROL_* events. Supported on endpoint agent 5.4.0 and later only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…re by default Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
LimaCharlie Cloud Security — code scanNo new code findings were introduced by this pull request. This check reports and never fails: no Scanned This comment is updated in place on every push to this pull request. |
|
Heads-up: #481 just merged a page at The sensor-side material here isn't covered by #481 and would be worth folding into the merged page: 🤖 Generated with Claude Code |
|
Closing as superseded by #481, which documents the current hive-based Application Control configuration. The sensor-side details in this PR could still be added to the merged page in a follow-up PR: |
Adds a page for the Application Control extension (
ext-app-control), at5-integrations/extensions/limacharlie/app-control.md, linked from the nav and the LimaCharlie extensions index.Supported only on endpoint agent 5.4.0 and later. This is stated in a warning right after the overview, in Requirements, and in the index entry.
Sections:
off,permissive,permissive_sync,enforcing.hive get/validate/setcommands.app_control_policyreply, status fields, and allAPP_CONTROL_DEGRADEDflags.APP_CONTROL_DENIED,APP_CONTROL_UNRESOLVED,APP_CONTROL_POLICY_REP, with fields and reason codes.Open items before merging:
…/extension-detail/ext-app-control) is assumed from the DLP pattern.POLICY_STALErow may need updating once that fix lands.🤖 Generated with Claude Code