Test Mode

In order to make sure that configured profile or rule works correctly, you can use the test mode, which imitates Application Control actions. In this mode, applications are not actually blocked but all activity is getting logged (see Application Control Events), as if the profile or rule was working as usual. The test mode is convenient for easy configuration of Application Control by an administrator when deployed an enterprise network.

To enable test mode for a profile

1.In the General section of profile properties, set the flag Enable profile to start using a profile (disabled by default).

2.Set the flag Switch profile to global test mode.

3.Click Save.

A profile in test mode will have the icon-profile-test icon in Profiles group of the anti-virus network tree. Process activity will not get blocked based on functional analysis criteria or deny and allow rules on stations with this profile assigned to them. Instead, statistics will be collected and displayed in the Anti-virus Network → Statistics → Application Control events section.

When a profile is in test mode, all verdicts a launched process would receive according to the flowchart below are written to the Application Control event log in their respective order.

scheme-application-control-test-mode

Flowchart step

Application Control event log entry

Match in deny rules

Blocked by deny rules

Match in allow rules

Allowed by allow rules

Match in trusted application group

YES: Allowed (found in the trusted application group)

NO: Blocked (not found in the trusted application group)

Denied by functional analysis criteria

Blocked after functional analysis

Allowed by functional analysis criteria

Allowed after functional analysis

For instance, if you have not configured any rules or a trusted application group but have enabled some functional analysis criteria in the Drivers loading category, then if a driver matching both deny and allow criteria is launched, the events Blocked after functional analysis and Allowed after functional analysis will be written consecutively to the event log in test mode. Such information is intended to help you analyze the operation logic of the profile so that you could configure it to match your needs more accurately.

Once you make sure that tested profile operates as you need, it needs to be switched from test mode to active mode. Active profile has the icon-profile icon in Profiles group of the anti-virus network tree.

To disable test mode for a profile

1.In the General section of profile properties, clear the flag Switch profile to global test mode.

2.Click Save.

Test mode can also be used to check how specific allow or deny rules work in a profile, without switching the profile entirely.

To enable test mode for allow or deny rule in a profile

1.In the Allow rules or Deny rules section of profile properties, select the rule you created and would like to test.

2.In the opened rule settings, set the Enable rule and Switch rule to test mode flags.

3.Click Save.

In this case process activity on stations is blocked based on the profile configuration, but only according to functional analysis criteria and those rules that are not functioning in test mode. Allow and deny rules in test mode work the same as profiles in this mode: their configuration does not cause any activity to be blocked, but every match is written to the activity log in the Application Control events section.

info

In contrast with profile test mode, there is no indication of any rules being in test mode on involved profile icon in the anti-virus network tree. Any active profile with rules in test mode would have the icon-profile icon.

Once you make sure the rule you are testing works properly, it needs to be switched from test mode to active mode.

To disable test mode for allow or deny rule in a profile

1.In the Allow rules or Deny rules section of profile properties, select the rule you are testing.

2.In the opened rule settings, clear the Switch rule to test mode flag.

3.Click Save.