Compliance with Mandos

With Mandos, you can combine the following:

  1. Allow one or many applications to execute based on the file hash.
  2. Deny one or many applications to execute based on the file hash.
  3. Allow application execution based on directory (including sub-directories).
  4. Allow application execution based on directory (including sub-directories).
  5. Configure a default rule that matches if none of the above match.

The following list shows the order by which rules are applied:

  1. An explicit hash match
  2. An explicit file match
  3. An explicit directory match
  4. The mode the daemon is running in (permit or enforce)

For more information, see “Managing the Mandos configuration file” in this FAQ list.