Skip to content

Document Application Control configuration (hives, events, permissions) - #481

Merged
maximelb merged 3 commits into
masterfrom
docs/app-control-hives
Oct 4, 2026
Merged

maximelb merged 3 commits into
masterfrom
docs/app-control-hives

Conversation

@maximelb

@maximelb maximelb commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Summary

  • New extension page for Application Control: what it does, platforms (Windows and macOS, sensor 5.4.0 or later), mode-by-mode rollout by tag, and how to read would-be blocks from the events.
  • New Config Hive pages for app_control_policy and app_control_rule, with JSON and CLI examples (Windows allowlist, staged rollout by tag, temporary exception via expiry).
  • APP_CONTROL_DENIED and APP_CONTROL_UNRESOLVED added to the EDR events reference.
  • app_control.get and app_control.set added to the permissions reference.
  • Nav entries and index/See Also links updated.

Overlap with #473

#473 also adds docs/5-integrations/extensions/limacharlie/app-control.md (plus the index and nav entries), so the two PRs conflict on those three files. This PR documents the two-hive configuration model (app_control_policy and app_control_rule), so the two pages need to be reconciled before either merges.

Checks

  • npx markdownlint-cli2: 0 issues
  • mkdocs build --strict: passes
  • scripts/check-list-numbering.py: 0 new breaks

🤖 Generated with Claude Code

Add the Application Control extension page, Config Hive pages for the
app_control_policy and app_control_rule hives, the APP_CONTROL_DENIED and
APP_CONTROL_UNRESOLVED events, and the app_control.get / app_control.set
permissions. Link them from the nav and the index pages.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
lcbill
lcbill previously approved these changes Oct 4, 2026
…cord disabled

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
lcbill
lcbill previously approved these changes Oct 4, 2026
@limacharlie-refractionpoint

limacharlie-refractionpoint Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

LimaCharlie Cloud Security — code scan

No new code findings were introduced by this pull request.

This check reports and never fails: no gating.fail_on is set on the code_scanning policy.

Scanned refractionPOINT/documentation 3f6b540…fca35f9 — only findings new in the head commit are listed; anything already on the base branch is the repository's own finding set, on the Cloud Security Code page.

This comment is updated in place on every push to this pull request.

@maximelb

maximelb commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

APP_CONTROL_IS_ENFORCED, APP_CONTROL_MODE and APP_CONTROL_DECISION are
numbers on the wire (confirmed on live events), so the example D&R rule
matching false would never fire; it now matches 0. Removing a tag only
steps a sensor back when a broader policy still matches it; a sensor that
matches nothing keeps its last policy.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@maximelb
maximelb merged commit 5b500e0 into master Oct 4, 2026
7 checks passed
@maximelb
maximelb deleted the docs/app-control-hives branch October 4, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants