Skip to content

Choose a Runtime Protection

Use detection to identify activity, blocking to stop matching operations, and application restrictions to define what a program may do. These controls serve different purposes.

Your goalWorkspaceEffect
Find suspicious activityDetect > Runtime DetectionProduces matches and the configured response when collected activity meets a rule.
Stop a matching operationRespond > Runtime BlocksDenies the operation or terminates the matching process, depending on the policy.
Limit one application's behaviorRuntime Blocks > Application RestrictionsAudits or enforces the application's allowed behavior.
Reduce expected anomaly noiseBehavioral Analytics > Anomaly ExceptionsExcludes matching behavior from normal anomaly results without stopping event collection.

Start with detection

Open Detect > Runtime Detection. Review Built-in Rules, or create a rule in Custom Rules. Use Recent Matches to inspect the activity that triggered a rule.

Detection is not proof that an operation was blocked. Use Runtime Detection for the creation and review workflow.

Apply a runtime block

  1. Open Respond > Runtime Blocks > Security Policies.
  2. Select a policy and review its stated action.
  3. Choose a limited target scope and inspect the available impact preview.
  4. Review the activation confirmation and activate the policy.
  5. Check the delivery result for each target sensor.

An impact preview describes observed activity, not every operation the policy could affect. Test the policy on a representative host before expanding its scope.

Runtime Blocks policy templates and impact review.
Review the selected policy and its impact before activation. Click to enlarge

For a policy you author yourself, use Custom Policies. See Runtime Blocks for inspection, editing, activation, and removal.

Restrict an application

Use Application Restrictions when you want to define an application's allowed child processes, files, destinations, and capabilities. Start in observation mode, review the allowed behavior, and use audit mode before enforcement.

See Application Restrictions.

Exclude expected anomalies

Use Anomaly Exceptions for a known, expected pattern. Choose the smallest scope, record a reason, and set an expiry where appropriate.

An anomaly exception does not disable Runtime Blocks or silence every alert source. See Anomaly Exceptions.

Existing deployments

The separate Policy Pack assignment and Guardian Policies screens have been retired. Manage existing detection rules in Runtime Detection. Previously assigned sensor policies are not automatically removed.

Released under the Telovix Commercial License.