The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Add Exclusion or Edit Exclusion

Prev Next

You can exclude a process, caller module, API, signature, IP address, Host name, or service from Exploit Prevention.

When specifying exclusions, consider the following:

  • Based on the type selected from the Exclusion Type drop-down list, you must specify at least one of Files-Processes-Registry, Caller Module, API, Signatures, Service Name, or IP Addresses.
  • If you specify more than one identifier, all identifiers apply.
  • If you specify more than one identifier and they don't match, the exclusion is invalid. For example, the file name and MD5 hash don't apply to the same file.
  • Exclusions are case insensitive.
  • If you include signature IDs in an exclusion, the exclusion only applies to the process in the specified signatures. If no signature IDs are specified, the exclusion applies to the process in all signatures.
  • For Process exclusions, you must specify at least one identifier: File name or path, MD5 hash, or Signer.
  • Exclusions with Caller Module or API don't apply to DEP.
  • When the Process section fields (File name or path, MD5 hash, Signer, User SID, Group SID, User name, Group name, or Hostname) are active, the Target section field (File name or path or Registry key or value) is disabled by default and vice versa.
  • Wildcards are allowed for all except User SID, Group SID, User name, Group name, MD5 hash, and Signature IDs.
  • Target, User SID, Group SID, User name, Group name, and Hostname only apply to Files-Process-Registry.
Options
Section Option Definition
Name Specifies the exclusion name. This field is required with at least one other field whichever object field is applicable to the Exclusion Type.

Note

This field is applicable only for Files-Processes-Registry.

Process (Initiator process)

Files-Processes-Registry, Buffer Overflow, or Illegal API Use

Name

Specifies the initiator process name to exclude. Exploit Prevention. This field is required with at least one other field: File name or path, MD5 hash, or Signer.

Note

This field is not applicable for Files-Processes-Registry.

File name or path Specifies (comma-separated) file name or path of the executable to add or edit.

Click Browse to select the executable.

MD5 hash Indicates the MD5 hash (32-digit hexadecimal number) of the process.
Signer Enable digital signature checkGuarantees that code hasn't been changed or corrupted since it was signed with cryptographic hash.

If enabled, specify:

  • Allow any signature — Allows files signed by any process signer.
  • Signed by — Allows only files signed by the specified process signer.

    A signer distinguished name (SDN) for the executable is required and it must match exactly the entries in the accompanying field, including commas and spaces.

    The process signer appears in the correct format in the events in the log files. For example:

    C=US, ST=WASHINGTON, L=REDMOND, O=MICROSOFT CORPORATION, OU=MOPR, CN=MICROSOFT WINDOWS

    Note

    You can enter

    S

    for the state or ProvinceName object identifier, but the element automatically appears as

    ST

    in the log files.

Process

Files-Processes-Registry only

User SID Specifies User Security Identifier.

Note

If this field is enabled, then User name will be disabled.

Group SID Specifies Group Security Identifier.

Note

If this field is enabled, then Group name will be disabled.

User name Specifies the user name.

Note

If this field is enabled, then User SID will be disabled.

Group name Specifies the group name.

Note

If this field is enabled, then Group SID will be disabled.

Host name Specifies the exclusion by host name.

Note

This field is applicable only for Files-Processes-Registry.

Target

Files-Processes-Registry only

File name or path Specifies (comma-separated) target file, process, or section.

Note

If this field is enabled, then Registry key or value will be disabled.

Registry key or value Specifies registry key or value.

Note

If this field is enabled, then File name or path will be disabled.

Caller Module

Buffer Overflow or Illegal API Use

Name Specifies the name of the module (a DLL) loaded by an executable that owns the writable memory that makes the call.

This field is required with at least one other field: File name or path, MD5 hash, or Signer.

File name or path Specifies the file name or path of the executable to add or edit.

Click Browse to select the executable.

MD5 hash Indicates the MD5 hash (32-digit hexadecimal number) of the process.
Signer Enable digital signature checkGuarantees that code hasn't been changed or corrupted since it was signed with cryptographic hash.

If enabled, specify:

  • Allow any signature — Allows files signed by any process signer.
  • Signed by — Allows only files signed by the specified process signer.

    A signer distinguished name (SDN) for the executable is required and it must match exactly the entries in the accompanying field, including commas and spaces.

    The process signer appears in the correct format in the events in the log files. For example:

    C=US, ST=WASHINGTON, L=REDMOND, O=MICROSOFT CORPORATION, OU=MOPR, CN=MICROSOFT WINDOWS

    Note

    You can enter

    S

    for the state or ProvinceName object identifier, but the element automatically appears as

    ST

    in the log files.

API

Buffer Overflow or Illegal API Use

Name Specifies the name of the API (application programming interface) being called.
Signatures

Files-Processes-Registry, Buffer Overflow, Illegal API Use, or Network IPS

Signature IDs Specifies (comma-separated) Exploit Prevention signature identifiers.

Invalid or non-existent signatures are not allowed.

Note

Signature-based exclusion for Files-Processes-Registry is applicable to Trellix-Default rules and Expert rules (Custom rules).

IP Addresses

Network IPS only

IP addresses or ranges Specifies (comma-separated) IP addresses (in IPv4 format) or ranges. Enter the starting point and ending point of the range.

For example: 203.0.113.0-203.0.113.255

Services

Services only

Service Name Specifies the name of the service, such as AdobeARM, from the Services tab in Task Manager.
Notes Provides more information about the item.