Skip to content

Application Control

Overview


Application Control is used to block various applications in the Crystal Eye XDR network. There is a list of applications that can be banned which are classified under various categories such as Arts & Entertainment, Mail, Messaging and Forums, News, File Sharing, Shopping, Social Media, and Technology. The Crystal Eye XDR administrators can also Whitelist an IP Address to access an application.

Installation


The Application Control feature is not available by default. It can be installed from Marketplace in the left-hand navigation panel.


Left-hand Navigation Panel > Security Configuration > Protocol Filtering > Application Control !

crystal-eye-xdr-application-filter-navigation

Block Applications


The Block Applications filter can be used to select the applications that are required to be blocked.

Step 1: In the Application Filter application page, click the Edit button under the Blocked Application section

crystal-eye-xdr-application-filter-blocked-applications

Step 2: You will now see the Block Application section. Click the tick box positioned against the application that needs to be blocked and click the Update button.

crystal-eye-xdr-application-filter-blocked-application-section

Creating a Whitelist


The Crystal Eye XDR administrators can easily whitelist the application or website by adding its IP address to the whitelist section.

How to Create a Whitelist of IP Addresses Using the Application Control?

Step 1: In the Application Filter application page, click the Add button of the Whitelist section.

crystal-eye-xdr-application-filter-whitelist

Step 2: You will now see the Whitelist section. Enter the IP Address in the IP Address textbox and click the Add button.

crystal-eye-xdr-application-filter-whitelist-2

Crystal Eye's Secure Web Gateway (SWG) helps protect users from web-based threats, enforces web access policies, and ensures compliance through integrated filtering, blocking, and monitoring tools. This guide provides step-by-step instructions to help end users configure and manage the SWG effectively.

Creating Application Control Profiles

crystal-eye-xdr-application-filter-create-profile

  1. Open the Application Control app.
  2. Click Add Profile.
  3. Fill in the following: Name: A unique name for the profile (e.g., "Block Social Media"). Description: A short explanation (optional). Block By: Choose "protocols" to block specific applications. Choose "risk_rating" to block apps based on their risk score (1-5). Blocked Applications: Select from predefined apps if "protocols" was chosen. Risk Rate: Select a number between 1 (low) to 5 (high) if "risk_rating" was chosen.
  4. Click Save.

crystal-eye-xdr-application-filter-select-category

Applying Profiles in Advanced Firewall

  1. Navigate to Advanced Firewall > Traffic Rules.
  2. Click Add Rule.
  3. Set the rule parameters: Source/Destination IPs or user groups (SSO-integrated). Under Target, select Application Control. Choose the Application Control profile created earlier.
  4. Click Apply to enforce the rule.

Viewing Block Reports

  1. Go to Threat Hunt Dashboard.
  2. Locate the Application Control Blocks table.
  3. Use filters to refine data by date, source IP, destination IP, and port.

Logging and Audit Trail

All policy changes are recorded.

Go to Log Viewer to view config update history.