You can add a list of monitored applications you want to exclude from Exploit Guard processing (both exploit detection and exploit prevention) using the Web UI or the API.
Important
The excludedPaths is the only value that will completely exclude a specific process.
File paths should not be included in the excludedPaths list.
The Endpoint Security (HX) server does not validate monitored application entries included in your Exploit Guard exclusion list. You must confirm your application exclusions are correct.
To add monitored application exclusions for all host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to access the Edit Policy page.
Select the Exploit Guard Protection tab.
In the Policy Exclusions section, specify the executable file name of a monitored application (process) you want to exclude from Exploit Guard processing in the field under the Exclude monitored applications from Exploit Guard. For example, adding
chrome.exeto the exclusion list will exclude Chrome from Exploit Guard processing.Click Add to add the monitored application to the list.
Repeat Steps 5 and 6 until you have added all the monitored applications you want to the list.
Click Save.
To add monitored application exclusions for selected host sets:
Note
NOTE: See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Exploit Guard Protection tab.
In the Policy Exclusions section, specify the name of a monitored application you want to exclude from Exploit Guard processing in the field under the Exclude monitored applications from Exploit Guard.
Click Add to add the monitored application to the list.
Repeat Steps 5 and 6 until you have added all the monitored applications you want to the list.
Click Save.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.