Application catalog
Discover, review, and manage applications observed across your fleet
Application catalog
Threatmatic automatically builds an application catalog for your organization as agents report traffic from enrolled endpoints. Every application seen sending or receiving network traffic is recorded — giving you a continuously updated inventory of what is running across your fleet.
How it works
When a Threatmatic agent observes a network event, it captures the application responsible for the connection. The application's name and identifier are normalized and stored in the catalog scoped to your organization.
Each catalog entry includes:
| Field | Description |
|---|---|
| App ID | Normalized identifier (e.g. exe name or bundle ID) |
| Title | Human-readable display name |
| Blocked | Whether the app is explicitly denied across the org |
| Tags | Labels for grouping and policy targeting |
| Documentation | Optional notes for your team (e.g. owner, purpose, risk) |
Review discovered applications
- Navigate to Metrics → Applications
- Browse or search the list of applications observed on your enrolled devices
- Click any entry to view its traffic history and current policy status
Block an application
Setting an application as blocked prevents it from making or receiving network connections on any enrolled device in your organization.
- Open the application entry in the catalog
- Toggle Blocked to on
- Save — the block takes effect across all enrolled devices immediately
Blocking a system process (e.g. svchost.exe) will affect all traffic routed through that
process. Review the application's traffic history before blocking.
Tag an application
Tags let you reference groups of applications in policy rules without hardcoding individual names.
- Open the application entry
- Add one or more tags (e.g.
remote-access,sanctioned,under-review) - Save — the tags are immediately available for use in policies
Next steps
How is this guide?
Last updated on