Hello Sasa,
I forgot to mention the most important point...
When I download and run an unknown/untrusted app and the Behavior Blocker alerts I then select the Quarantine option.
EIS allows the option to copy the quarantined file(s) and paste to a location of my choice where I can do further investigation - which is usually upload and scan at VirusTotal.
If the files are not classified as malware by at least 5 AV vendors then I proceed with caution. However, if the 5 AV vendors are made up entirely of the top-tier AV companies, for example ...ESET, Emsi, Kasper, BitD, Avira, Trend... then I just Quarantine and delete unless I think it worthwhile to pursue any further investigation.
With default settings the Behavior Blocker is not automated...it requires the user to make decisions.
If you were to manually super-tweak the Behavior Blocker rules for each individual application, then it would be fully automated...but all that rigmarole is superfluous...
hjlbx