Link to home
Create AccountLog in
Azure

Azure

--

Questions

--

Followers

Top Experts

Avatar of Leo
Leo🇦🇺

Application Whitelisting - Airlock Use Cases

We are looking to implementing Application Control into our environment to comply with the controls of the Australian Cyber Security’s Essential Eight strategy. We are in the process of listing Proof of Concept (PoC) of the Airlock Digital application control platform to validate the suitability of the tool for our environment, which contains many complex industry specific and in-house developed applications. 

 

I have listed Use cases for Airlock, kindly let me know if anything is missing, should be taken out or not required?

Item.Description
Environment 
Agent support on multiple OS versionsClient agent available on Windows, Linux and MacOS
Multiple Deployment OptionsOn-Premise / Cloud management server
Management 
Centralized Management ConsoleSingle console to manage everything
Role-Based Access ControlDiffering levels of permissions
Allowlisting Mechanism 
Cryptographic File Hash IdentificationIdentify allowlist item by cryptographic file hash 
Utilise SHA-256 File Hash as Minumum Minimum SHA-256 file hashing algorithm for allowlist enforcement
Software Publisher/Signature Identification Allowlist based on trusted signed software
File PathAllowlist based on file path
Parent ProcessAllowlist based on process information
Blocklist FunctionalityAbility to overide allowlist with blocklist rules
Trusted InstallerAbility to allowlist based on SCCM/Intune deployment
Allowlist Maintenance 
Block EventAdd to allowlist based on blocked events
Testing or Audit ModeTest allowlist without impact
Client RequestAdd to allowlist based on client request
File Reputation ReferenceLeverage reputation attributes for identification
Policy Configuration 
Policies for Different Asset GroupsPolicies based on device groups
Bypass Mechanism 
Manual Bypass Bypass without changing any policy
Time-LimitedBypass based on a time limit
Self ServiceBypass based on policy and/or user group
Bypass Capture/ReconcilicationAdd to allowlist based on bypassed activity
Enforcement 
Block Programs (Excutables)Block executable files
Block Software Libraries (dlls)Block software libraries and linked executables
InstallersBlock application installers
Block ScriptsBlock scripts engines and script files
Covers all accessible storageEnforce allowlist across all storage devices 
Visibility 
Real-time loggingProvide log output in real-time
Log all blocked executionsAbility to log blocked executions
Log trusted executionsAbility to log allowed executions

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


ASKER CERTIFIED SOLUTION
Avatar of btanbtan

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

Avatar of LeoLeo🇦🇺

ASKER

Thanks. Want clarification on two points;

 

1)“Missing Airlock existence - this signal asset not having airlock calling back” 

Can you please elaborate what do you mean by “signal asset not having airlock calling back”? 

 

2)“Allowlist binaries in priority” Are you referring to application binaries? and “the engine need to enforce the strictest match like folder, path vs hash” what are we matching? application binary folders?

 

Thanks for your feedback, anything else you can think off?

 

 

 


For 1, it is more to uninstall airlock hence centrally you see one of the asset no longer in the list of managed device. 

 

For 2, it is more of the apps binaries that is applied with multiple airlock allowed list rules, what is the resultant action to take by Airlock for enforcement. More of clarity of the enforcement state for the binaries 

 

 


Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.

Azure

Azure

--

Questions

--

Followers

Top Experts

Microsoft Azure is a cloud computing platform and infrastructure for building, deploying and managing applications and services through datacenters. It provides both platform-as-a-service (PaaS) and infrastructure-as-a-service (IaaS) services and supports many different programming languages, tools and frameworks, including both Microsoft-specific and third-party software and systems. Cloud Services is a PaaS environment and can be used to create scalable applications and services; there are specific software development kits (SDKs) provided by Microsoft for Python, Java, Node.js and .NET. Azure also has file and storage services, data management, analytics and DNS services.