Can the App Control agent prevent a file from being created (written) based on it's reputation score?
Environment
App Control Agent: All Supported Versions
Resolution
No, App Control was not designed to prevent writes based off of reputation score.
App Control's "Default-Deny" prevention capability stops malware, ransomware, zero-day, and non-malware attacks by default in High Enforcement Mode. Unapproved "Interesting" files will not run until approved.
Although it's not reputation based, File Integrity Control rules allow you to control modifications to one or more folders (or files). You can write-protect the folder (or file) by choosing Block as the Write Action, or you can monitor (but not block) changes by choosing Report as the Write Action. For more information see the user guide section Custom Software Rules > Custom Rule Types and Examples.