Choose a Runtime Protection
Use detection to identify activity, blocking to stop matching operations, and application restrictions to define what a program may do. These controls serve different purposes.
| Your goal | Workspace | Effect |
|---|---|---|
| Find suspicious activity | Detect > Runtime Detection | Produces matches and the configured response when collected activity meets a rule. |
| Stop a matching operation | Respond > Runtime Blocks | Denies the operation or terminates the matching process, depending on the policy. |
| Limit one application's behavior | Runtime Blocks > Application Restrictions | Audits or enforces the application's allowed behavior. |
| Reduce expected anomaly noise | Behavioral Analytics > Anomaly Exceptions | Excludes matching behavior from normal anomaly results without stopping event collection. |
Start with detection
Open Detect > Runtime Detection. Review Built-in Rules, or create a rule in Custom Rules. Use Recent Matches to inspect the activity that triggered a rule.
Detection is not proof that an operation was blocked. Use Runtime Detection for the creation and review workflow.
Apply a runtime block
- Open Respond > Runtime Blocks > Security Policies.
- Select a policy and review its stated action.
- Choose a limited target scope and inspect the available impact preview.
- Review the activation confirmation and activate the policy.
- Check the delivery result for each target sensor.
An impact preview describes observed activity, not every operation the policy could affect. Test the policy on a representative host before expanding its scope.

For a policy you author yourself, use Custom Policies. See Runtime Blocks for inspection, editing, activation, and removal.
Restrict an application
Use Application Restrictions when you want to define an application's allowed child processes, files, destinations, and capabilities. Start in observation mode, review the allowed behavior, and use audit mode before enforcement.
Exclude expected anomalies
Use Anomaly Exceptions for a known, expected pattern. Choose the smallest scope, record a reason, and set an expiry where appropriate.
An anomaly exception does not disable Runtime Blocks or silence every alert source. See Anomaly Exceptions.
Existing deployments
The separate Policy Pack assignment and Guardian Policies screens have been retired. Manage existing detection rules in Runtime Detection. Previously assigned sensor policies are not automatically removed.