LogoThreatmatic
Identity

Application catalog

Discover, review, and manage applications observed across your fleet

Application catalog

Threatmatic automatically builds an application catalog for your organization as agents report traffic from enrolled endpoints. Every application seen sending or receiving network traffic is recorded — giving you a continuously updated inventory of what is running across your fleet.

How it works

When a Threatmatic agent observes a network event, it captures the application responsible for the connection. The application's name and identifier are normalized and stored in the catalog scoped to your organization.

Each catalog entry includes:

FieldDescription
App IDNormalized identifier (e.g. exe name or bundle ID)
TitleHuman-readable display name
BlockedWhether the app is explicitly denied across the org
TagsLabels for grouping and policy targeting
DocumentationOptional notes for your team (e.g. owner, purpose, risk)

Review discovered applications

  1. Navigate to Metrics → Applications
  2. Browse or search the list of applications observed on your enrolled devices
  3. Click any entry to view its traffic history and current policy status

Block an application

Setting an application as blocked prevents it from making or receiving network connections on any enrolled device in your organization.

  1. Open the application entry in the catalog
  2. Toggle Blocked to on
  3. Save — the block takes effect across all enrolled devices immediately

Blocking a system process (e.g. svchost.exe) will affect all traffic routed through that process. Review the application's traffic history before blocking.

Tag an application

Tags let you reference groups of applications in policy rules without hardcoding individual names.

  1. Open the application entry
  2. Add one or more tags (e.g. remote-access, sanctioned, under-review)
  3. Save — the tags are immediately available for use in policies

Next steps

How is this guide?

Last updated on

On this page