You can exclude a process, caller module, API, signature, IP address, Hostname, or service from Exploit Prevention.
When specifying exclusions, consider the following:
Based on the type selected from the Exclusion Type drop-down list, you must specify at least one of Files-Processes-Registry, Caller Module, API, Signatures, Service Name, or IP Addresses.
If you specify more than one identifier, all identifiers apply.
If you specify more than one identifier and they don't match, the exclusion is invalid. For example, the file name and MD5 hash don't apply to the same file.
Wildcards are allowed for all except User SID, Group SID, User name, Group name, MD5 hash, and Signature IDs.
If you include signature IDs in an exclusion, the exclusion only applies to the process in the specified signatures. If no signature IDs are specified, the exclusion applies to the process in all signatures.
For Process exclusions, you must specify at least one identifier: File name or path, MD5 hash, or Signer.
Exclusions with Caller Module or API don't apply to DEP.
When the Process section fields (File name or path, MD5 hash, Signer, User SID, Group SID, User name, Group name, or Hostname) are active, the Target section fields (File name or path or Registry key or value) is disabled by default and vice versa.
Target, User SID, Group SID, User name, Group name, and Hostname only apply to Files-Processes-Registry.
Section | Option | Definition |
|---|---|---|
Name | Specifies the exclusion name. This field is required with at least one other field whichever object field is applicable to the Exclusion Type.
| |
Process (Initiator process) Files-Processes-Registry, Buffer Overflow, or Illegal API Use | Name | Specifies the initiator process name to exclude. Exploit Prevention excludes the process wherever it is located. This field is required with at least one other field: File name or path, MD5 hash, or Signer.
|
File name or path | Specifies (comma-separated) file name or path of the executable to add or edit. Click Browse to select the executable. | |
MD5 hash | Indicates the MD5 hash (32-digit hexadecimal number) of the process. | |
Signer | Enable digital signature check — Guarantees that code hasn't been changed or corrupted since it was signed with cryptographic hash. If enabled, specify:
From Trellix ePO - On-prem Event Log, copy and paste the details from the Source Signer Process field from an Endpoint Security event. | |
Process Files-Processes-Registry only | User SID | Specifies User Security Identifier.
|
Group SID | Specifies Group Security Identifier.
| |
User name | Specifies the user name.
| |
Group name | Specifies the group name.
| |
Hostname | Specifies exclusion by hostname.
| |
Target Files-Processes-Registry only | File name or path | Specifies (comma-separated) target file, process, or section.
|
Registry key or value | Specifies registry key or value.
| |
Caller Module Buffer Overflow or Illegal API Use | Name | Specifies the name of the module (a DLL) loaded by an executable that owns the writable memory that makes the call. This field is required with at least one other field: File name or path, MD5 hash, or Signer . |
File name or path | Specifies the name of the module (a DLL) loaded by an executable that owns the writable memory that makes the call. Click Browse to select the executable. | |
MD5 hash | Indicates the MD5 hash (32-digit hexadecimal number) of the process. | |
Signer | Enable digital signature check — Guarantees that code hasn't been changed or corrupted since it was signed with cryptographic hash. If enabled, specify:
From Trellix ePO - On-prem Event Log, copy and paste the details from the Source Signer Process field from an Endpoint Security event. | |
API Buffer Overflow or Illegal API Use | Name | Specifies the name of the API (application programming interface) being called. |
Signatures Files-Processes-Registry, Buffer Overflow, Illegal API Use, or Network IPS | Signature IDs | Specifies (comma-separated) Exploit Prevention signature identifiers. Invalid or non-existent signatures are not allowed.
|
IP Addresses Network IPS only | IP addresses or ranges | Specifies (comma-separated) IP addresses (in IPv4 format) or ranges. Enter the starting point and ending point of the range. For example: |
Services Services only | Service Name | Specifies the name of the service, such as AdobeARM, from the Services tab in Task Manager. |
Notes | Provides more information about the item. |