You can exclude a process, caller module, API, signature, IP address, Host name, or service from Exploit Prevention.
When specifying exclusions, consider the following:
- Based on the type selected from the Exclusion Type drop-down list, you must specify at least one of Files-Processes-Registry, Caller Module, API, Signatures, Service Name, or IP Addresses.
- If you specify more than one identifier, all identifiers apply.
- If you specify more than one identifier and they don't match, the exclusion is invalid. For example, the file name and MD5 hash don't apply to the same file.
- Exclusions are case insensitive.
- If you include signature IDs in an exclusion, the exclusion only applies to the process in the specified signatures. If no signature IDs are specified, the exclusion applies to the process in all signatures.
- For Process exclusions, you must specify at least one identifier: File name or path, MD5 hash, or Signer.
- Exclusions with Caller Module or API don't apply to DEP.
- When the Process section fields (File name or path, MD5 hash, Signer, User SID, Group SID, User name, Group name, or Hostname) are active, the Target section field (File name or path or Registry key or value) is disabled by default and vice versa.
- Wildcards are allowed for all except User SID, Group SID, User name, Group name, MD5 hash, and Signature IDs.
- Target, User SID, Group SID, User name, Group name, and Hostname only apply to Files-Process-Registry.
| Section | Option | Definition |
|---|---|---|
| Name | Specifies the exclusion name. This field is required with at least one other field whichever object field is applicable to the
Exclusion Type.
|
|
| Process (Initiator process)
Files-Processes-Registry, Buffer Overflow, or Illegal API Use |
Name |
Specifies the initiator process name to exclude. Exploit Prevention. This field is required with at least one other field: File name or path, MD5 hash, or Signer.
|
| File name or path | Specifies (comma-separated) file name or path of the executable to add or edit.
Click Browse to select the executable. |
|
| MD5 hash | Indicates the MD5 hash (32-digit hexadecimal number) of the process. | |
| Signer |
Enable digital signature check —
Guarantees that code hasn't been changed or corrupted since it was signed with cryptographic hash.
If enabled, specify:
|
|
| Process
Files-Processes-Registry only |
User SID | Specifies
User Security Identifier.
|
| Group SID | Specifies
Group Security Identifier.
|
|
| User name | Specifies the user name.
|
|
| Group name | Specifies the group name.
|
|
| Host name | Specifies the exclusion by host name.
|
|
| Target
Files-Processes-Registry only |
File name or path | Specifies (comma-separated) target file, process, or section.
|
| Registry key or value | Specifies registry key or value.
|
|
|
Caller Module
Buffer Overflow or Illegal API Use |
Name | Specifies the name of the module (a DLL) loaded by an executable that owns the writable memory that makes the call.
This field is required with at least one other field: File name or path, MD5 hash, or Signer. |
| File name or path |
Specifies the file name or path of the executable to add or edit.
Click Browse to select the executable. |
|
| MD5 hash | Indicates the MD5 hash (32-digit hexadecimal number) of the process. | |
| Signer |
Enable digital signature check —
Guarantees that code hasn't been changed or corrupted since it was signed with cryptographic hash.
If enabled, specify:
|
|
|
API
Buffer Overflow or Illegal API Use |
Name | Specifies the name of the API (application programming interface) being called. |
| Signatures
Files-Processes-Registry, Buffer Overflow, Illegal API Use, or Network IPS |
Signature IDs | Specifies (comma-separated) Exploit Prevention signature identifiers.
Invalid or non-existent signatures are not allowed.
|
| IP Addresses
Network IPS only |
IP addresses or ranges | Specifies (comma-separated) IP addresses (in IPv4 format) or ranges. Enter the starting point and ending point of the range.
For example: 203.0.113.0-203.0.113.255 |
| Services
Services only |
Service Name | Specifies the name of the service, such as AdobeARM, from the Services tab in Task Manager. |
| Notes | Provides more information about the item. |