TrellixEndpoint Security

    Application and Change Control

    Allowlisting and file integrity monitoring that survive contact with a real change window.

    Trellix Application and Change Control blocks unauthorised executables and unapproved changes to critical files, directories, and configurations — using a dynamic trust model so new software arriving through trusted channels is accepted automatically, without labour-intensive list management. Faltrox tunes the policy so it protects fixed-function and legacy systems without stopping the business.

    Overview

    What Application and Change Control is

    Trellix Application and Change Control blocks unauthorised executables and unapproved changes to critical files, directories, and configurations. It combines application allowlisting — only known-good software runs — with change control that enforces and monitors modifications to the system, registry, and user accounts. Together they ensure system integrity by allowing only authorised access and taking a systematic approach to preventing change.

    The differentiator is a dynamic trust model: new software arriving through trusted channels is accepted automatically, so a strict allowlist does not break patching or generate a flood of exceptions. It is built for the systems that are hardest to secure any other way — fixed-function devices, point-of-sale terminals, legacy servers, and disconnected machines that cannot take a modern patch cadence. Faltrox tunes the policy so it protects those systems without stopping the business.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Servers & Virtual Machines

    Enforces controls on connected or disconnected servers and VMs across the estate.

    02

    Point-of-Sale Terminals

    Locks down POS terminals to only approved software — a primary PCI-DSS use case.

    03

    Legacy & Unpatched Systems

    Protects legacy systems that cannot be patched on a modern cadence by allowlisting what runs.

    04

    Fixed-Function Devices

    Secures embedded and fixed-function devices where an antivirus agent is impractical.

    05

    Critical Files & Registry

    Blocks and logs unauthorised changes to system files, directories, configurations, and registry keys.

    06

    Zero-Day & APT Execution

    Prevents zero-day and APT attacks by blocking execution of anything not on the allowlist.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Inventory

      Groups every binary — EXEs, DLLs, drivers, and scripts — across the enterprise by application and vendor, and classifies them as known-good, unknown, or known-bad.

    2. 02

      Set Posture

      You choose the enforcement posture per system class: Default Deny (allowlist), Detect and Deny (reputation-based), or Verify and Deny (sandbox-verified).

    3. 03

      Enforce

      Unauthorised executables are blocked and out-of-policy changes to files, registry, and configuration are prevented before they occur.

    4. 04

      Monitor

      Real-time file integrity monitoring captures the who, when, what, and why of every change in one place, for PCI-DSS validation and outage root-cause.

    5. 05

      Manage Exceptions

      Dynamic trust accepts software from trusted updaters automatically, while a suggestions interface and self-approval workflow handle the rest without a ticket queue.

    Capabilities

    Key capabilities

    Dynamic Allowlisting

    Automatically accepts new software added through trusted channels — trusted users, groups, certificates, processes, and directories — so patching does not require a manual allowlist update every cycle.

    Three Enforcement Postures

    Default Deny (allowlist or trusted updaters), Detect and Deny (reputation-based), and Verify and Deny (sandbox-verified). You pick the posture per system class instead of accepting one global setting.

    Reputation-Backed Classification

    Trellix Global Threat Intelligence supplies cloud reputation and Threat Intelligence Exchange supplies local reputation, classifying every binary as known-good, unknown, or known-bad.

    Real-Time File Integrity Monitoring

    Captures the who, when, what, and why of every change — user name, time, program, and file or registry content — in one place and in real time, for PCI-DSS validation and outage root-cause analysis.

    Change Windows and Filters

    Restrict changes by user, group, application, certificate, or web service, and to specific times and dates — for example, allowing Windows updates only between 2am and 4am on Tuesdays.

    Memory Protection

    Prevents allowlisted applications from being exploited via memory buffer overflow attacks on Windows, closing the gap where an approved binary becomes the attack vector.

    Fixed-Function and Legacy Coverage

    Enforces controls on connected or disconnected servers, virtual machines, endpoints, point-of-sale terminals, and legacy systems that cannot take a modern agent or a patch cadence.

    Self-Approval Workflow

    Explains to users why an application was blocked and lets them request or self-approve it, so a strict posture does not route every exception through the service desk.

    Specifications

    Technical detail

    Windows Versions
    8.3.x, 8.2.x, 8.1.x, 8.0.x, 7.0.x
    Linux Versions
    6.4.x, 6.3.x
    Windows & UNIX
    6.2.x, 6.1.x
    Management
    Trellix ePolicy Orchestrator (ePO); installable via Microsoft System Center
    Compliance
    PCI-DSS (QSA forms provided), SOX, SWAM/CPE, NIST CPE matching

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Application and Change Control for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Won't allowlisting break our patching and software updates?

    That is the failure mode of static allowlisting, and the Dynamic Trust Model is the answer to it. Software arriving through a trusted updater, user, certificate, process, or directory is accepted automatically, so normal patching continues without a policy change.

    02What happens when someone runs an application that is not on the list?

    It is blocked and the user is told why, with the option to self-approve or request approval. Administrators get a suggestions interface that recommends update policies based on actual execution patterns, so exceptions are managed from evidence rather than guesswork.

    03Can this cover our point-of-sale terminals and legacy servers?

    Yes — fixed-function devices, POS terminals, legacy systems, and disconnected servers are a primary use case. These are typically the systems that cannot be patched on a modern cadence, which is exactly why an allowlist is the right control for them.

    04Does it help with PCI-DSS?

    Its file integrity monitoring is built for PCI-DSS validation and it ships qualified security assessor (QSA) forms for reporting. Inventory Mode also maintains SWAM/CPE compliance while reducing CPU load on the endpoint.

    05How is Change Control different from Application Control?

    Application Control governs what is allowed to execute. Change Control governs what is allowed to be modified — system files, directories, registry, and configurations. They are sold and deployed together because attackers use both paths.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us