Skip to content Follow Gritellect on LinkedIn
Blog
App Control, explained by the people who have operated it at scale
Practical guidance on policy design, deployment, enforcement and recovery.
Fundamentals3 min read
The missing control plane for App Control for Business
Windows already enforces. What no vendor ships is the layer that decides what to trust, records who approved it, and takes it away again when it is no longer needed.
Fundamentals
8- 4 min
Every application control product identifies files the same way
- 5 min
Seven Windows security layers, and the gap each one closes
- 4 min
AppLocker and App Control, and why you probably need both
- 5 min
Agent based application control, or the engine already in Windows
- 4 min
You verify every user. Do you verify every executable?
- 8 min
App Control vs antivirus vs XDR, and why you need all three
- 7 min
Stop asking what is dangerous. Decide what belongs.
- 8 min
What is App Control for Business, and what happened to WDAC
Policy design
8- 5 min
Policy options that mean the opposite of what they read
- 5 min
Managed installer is not a convenience flag. It is a trust channel
- 6 min
One policy estate, a profile per business unit
- 5 min
Servers are critical assets. Endpoints are critical entry points
- 6 min
Catalog files do not remove hash management, they move it
- 3 min
An application that updates itself, and three ways out
- 11 min
Choosing App Control rule levels, and using version rules properly
- 7 min
Base and supplemental App Control policies, and how they really combine
Deployment
2Operations
3Troubleshooting
2Threats
3Drivers
2From the team on LinkedIn
We have been writing about this since well before the site existed
Running App Control
- Application control only lasts if it is staged, visible and measurable
- Before you enforce, know what will break
- Windows App Control is no longer optional for the enterprise
- Simplifying WDAC management with a control plane
- Audit mode to full enforcement, without the interruption
- What most deployments lack is not effort, it is a control plane
- Governance is what makes a WDAC rollout predictable
- Why application control implementations fail over time
Zero Trust, EDR and antivirus
- Zero Trust at the point of execution, and keeping it there
- When application control affects what your EDR can see
- Separate the request from the execution
- Identity controls are being bypassed, so extend the model
- Application control is Zero Trust applied to code
- Application control, EDR and antivirus each do a different job
Got a block you cannot explain?
If you have a code integrity event you cannot make sense of, send it over. We would rather answer the question than have you guess, and it usually turns into something worth writing about.