The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Add Exclusion or Edit Exclusion

Prev Next

You can exclude a process, caller module, API, signature, IP address, Hostname, or service from Exploit Prevention.

When specifying exclusions, consider the following:

  • Based on the type selected from the Exclusion Type drop-down list, you must specify at least one of Files-Processes-Registry, Caller Module, API, Signatures, Service Name, or IP Addresses.

  • If you specify more than one identifier, all identifiers apply.

  • If you specify more than one identifier and they don't match, the exclusion is invalid. For example, the file name and MD5 hash don't apply to the same file.

  • Wildcards are allowed for all except User SID, Group SID, User name, Group name, MD5 hash, and Signature IDs.

  • If you include signature IDs in an exclusion, the exclusion only applies to the process in the specified signatures. If no signature IDs are specified, the exclusion applies to the process in all signatures.

  • For Process exclusions, you must specify at least one identifier: File name or path, MD5 hash, or Signer.

  • Exclusions with Caller Module or API don't apply to DEP.

  • When the Process section fields (File name or path, MD5 hash, Signer, User SID, Group SID, User name, Group name, or Hostname) are active, the Target section fields (File name or path or Registry key or value) is disabled by default and vice versa.

  • Target, User SID, Group SID, User name, Group name, and Hostname only apply to Files-Processes-Registry.

Option definitions

Section

Option

Definition

Name

Specifies the exclusion name. This field is required with at least one other field whichever object field is applicable to the Exclusion Type.

Note

This field is applicable only for Files-Processes-Registry.

Process (Initiator process)

Files-Processes-Registry, Buffer Overflow, or Illegal API Use

Name

Specifies the initiator process name to exclude. Exploit Prevention excludes the process wherever it is located.

This field is required with at least one other field: File name or path, MD5 hash, or Signer.

Note

This field is not applicable for Files-Processes-Registry.

File name or path

Specifies (comma-separated) file name or path of the executable to add or edit.

Click Browse to select the executable.

MD5 hash

Indicates the MD5 hash (32-digit hexadecimal number) of the process.

Signer

Enable digital signature check — Guarantees that code hasn't been changed or corrupted since it was signed with cryptographic hash.

If enabled, specify:

  • Allow any signature — Allows files signed by any process signer.

  • Signed by — Allows only files signed by the specified process signer.

    A signer distinguished name (SDN) for the executable is required and it must match exactly the entries in the accompanying field, including commas and spaces.

    The process signer appears in the correct format in the events in the log files. For example:

    C=US, ST=WASHINGTON, L=REDMOND, O=MICROSOFT CORPORATION, OU=MOPR, CN=MICROSOFT WINDOWS

    Note

    You can enter S for the stateOrProvinceName object identifier, but the element automatically appears as ST in the log files.

From Trellix ePO - On-prem Event Log, copy and paste the details from the Source Signer Process field from an Endpoint Security event.

Process

Files-Processes-Registry only

User SID

Specifies User Security Identifier.

Note

If this field is enabled, then User name will be disabled.

Group SID

Specifies Group Security Identifier.

Note

If this field is enabled, then Group name will be disabled.

User name

Specifies the user name.

Note

If this field is enabled, then User SID will be disabled.

Group name

Specifies the group name.

Note

If this field is enabled, then Group SID will be disabled.

Hostname

Specifies exclusion by hostname.

Note

This field is applicable only for Files-Processes-Registry.

Target

Files-Processes-Registry only

File name or path

Specifies (comma-separated) target file, process, or section.

Note

If this field is enabled, then Registry key or value will be disabled.

Registry key or value

Specifies registry key or value.

Note

If this field is enabled, then File name or path will be disabled.

Caller Module

Buffer Overflow or Illegal API Use

Name

Specifies the name of the module (a DLL) loaded by an executable that owns the writable memory that makes the call.

This field is required with at least one other field: File name or path, MD5 hash, or Signer .

File name or path

Specifies the name of the module (a DLL) loaded by an executable that owns the writable memory that makes the call. Click Browse to select the executable.

MD5 hash

Indicates the MD5 hash (32-digit hexadecimal number) of the process.

Signer

Enable digital signature check — Guarantees that code hasn't been changed or corrupted since it was signed with cryptographic hash.

If enabled, specify:

  • Allow any signature — Allows files signed by any process signer.

  • Signed by — Allows only files signed by the specified process signer.

    A signer distinguished name (SDN) for the executable is required and it must match exactly the entries in the accompanying field, including commas and spaces.

    The process signer appears in the correct format in the events in the log files. For example:

    C=US, ST=WASHINGTON, L=REDMOND, O=MICROSOFT CORPORATION, OU=MOPR, CN=MICROSOFT WINDOWS

    Note

    You can enter S for the stateOrProvinceName object identifier, but the element automatically appears as ST in the log files.

From Trellix ePO - On-prem Event Log, copy and paste the details from the Source Signer Process field from an Endpoint Security event.

API

Buffer Overflow or Illegal API Use

Name

Specifies the name of the API (application programming interface) being called.

Signatures

Files-Processes-Registry, Buffer Overflow, Illegal API Use, or Network IPS

Signature IDs

Specifies (comma-separated) Exploit Prevention signature identifiers.

Invalid or non-existent signatures are not allowed.

Note

Signature-based exclusion for Files-Processes-Registry is applicable to Trellix-Default rules and Expert rules (Custom rules).

IP Addresses

Network IPS only

IP addresses or ranges

Specifies (comma-separated) IP addresses (in IPv4 format) or ranges. Enter the starting point and ending point of the range.

For example: 203.0.113.0-203.0.113.255

Services

Services only

Service Name

Specifies the name of the service, such as AdobeARM, from the Services tab in Task Manager.

Notes

Provides more information about the item.