Endpoint Security

    Only the software you trust is allowed to run

    Application Control is NetLock RMM's proprietary allowlisting engine for Windows โ€” built in-house, no third-party module. Define rulesets that describe exactly which executables may launch โ€” everything you did not explicitly allow is blocked.

    Try Demo
    Every launch attempt is checked against your rulesets โ€” allowed or blocked, in real time.
    application-control ยท live
    explorer.exe
    โ€ฆ\\C:\Windows
    ALLOWED
    Teams.exe
    โ€ฆ\\Microsoft\Teams
    ALLOWED
    unknown_setup.exe
    โ€ฆ\\Downloads
    BLOCKED
    powershell.exe
    โ€ฆ\\System32
    ALLOWED
    crypto-miner.exe
    โ€ฆ\\AppData\Temp
    BLOCKED
    Built In-House

    Proprietary NetLock RMM technology

    Application Control is fully developed by the NetLock RMM team โ€” not licensed, not white-labeled, not glued together from third-party SDKs.

    Native to the agent

    Embedded directly into the NetLock RMM agent โ€” no extra service, no extra process, no orphaned helper running on your endpoints.

    No third-party black box

    No vendor lock-in, no licensing cascade, no opaque engine. Every line of the detection logic is ours and is shipped under our roadmap.

    Built for RMM scale

    Designed from day one for multi-tenant fleets โ€” push rulesets to thousands of endpoints, manage exemptions per tenant, audit verdicts centrally.

    How allowlisting works

    Three steps to a locked-down endpoint

    Application Control turns a default-deny posture into a few clear configuration steps.

    1

    Author a ruleset

    Create a ruleset and add rules describing the executables you trust โ€” by path, hash, or signing certificate.

    2

    Attach it to a policy

    Attach the ruleset under Policy Settings, so every device the policy targets enforces the same allowlist.

    3

    Everything else is blocked

    Any executable not matched by a rule is blocked from running and the attempt is logged for review.

    Rule matching

    Precise rules, combined your way

    Rules match on file, version, and certificate attributes โ€” and conditions are combined so a rule is as tight as you need it.

    File path & version info

    Match on the executable's path and its version-info strings such as file company, product, copyright, and version.

    SHA256 & SHA512 hashes

    Match the exact binary by cryptographic hash โ€” the strongest, most tamper-resistant form of rule.

    Certificate owner & issuer

    Allow software from a trusted publisher by matching the signing certificate's owner and issuer.

    Certificate validity window

    Constrain a rule to certificates valid within a specific date range.

    Public key & serial

    Match the certificate's public key, serial number, and SHA1 thumbprint for signer-level precision.

    AND-combined conditions

    Stack multiple attributes on one rule โ€” every condition must match before an executable is allowed.

    Blocked Applications

    Turn a block into a rule in one click

    Every blocked launch lands on the Blocked Applications tab, ready to be reviewed and approved.

    Every block is logged

    Blocked launch attempts are captured with the executable details so nothing slips by unnoticed.

    Approve into allow rules

    Approve a blocked entry and the server promotes it to an allow rule โ€” deduplicated by SHA512 hash.

    Clear review states

    Each blocked entry carries a status so your team always knows what still needs a decision.

    Pending approvalApprovedDismissed
    Blocked Applications tab

    Windows-only, enforced through policies

    Application Control rulesets enforce nothing until attached under Policy Settings โ†’ Windows โ†’ Application Control. Authoring and enforcement stay cleanly separated, so you can build and test a ruleset before any device feels it.

    Lock down what runs on every endpoint

    Default-deny application control, without the management overhead.

    View Pricing