CIS is great. But it is difficult to locate an application in policies management, no matter in firewall or defense+, especially when you have dozens of applications. Why not just add a search function to help us locate an application quickly in policies management?
In addition, can the defense+'s priorities be more explicit? I define a custom policy for an application, but the result is not what I expect. Some policies affect my custom policy, and even I put the custom policy on the top, the policy still does not work.
There is a hidden Ctrl + F function in the firewall/d+ policy interface. But it requires you to type in the exact path, but i believe a better search function is in store for some later versions.
Tip for looking up Windows system files using Search: start typing %windir%\ and you will suggestions in the drop down box underneath the search field.
a). the list took focus so that the wheel worked without having to click and
b). the list stayed where it was left before using e.g. Delete - sometimes it jumps back to the top which, with a long list, means trying to find where you were. As the files are ‘in no particular order’, this can be difficult.
I don’t suppose it’d be possible to sort on the filename column using the last element (filename.exe), would it?
I agree if you say: the order of the rules inside one policy in FW is important. I don’t see any problem if svchost (or WOS, SYSTEM) appears before or after Firefox for an example. At least I don’t have any problem with this in my system.
I disagree about D+ and AV policies order (including exclusions). Order does matter? How does CIS takes this?
edit:
About groups: just use its name for sorting! Or, put them on top or bottom. Not so complicated.
For example, one thing I am thinking of doing is having a group at the bottom of my security policy to block certain things so they are automatically blocked for all new application that would be added below but not blocked for existing applications. This would not work if sorted.
It would be ok if individual rules were sorted between the group rules. This would be helpful.