Before you install or upgrade the xAgent software

Prev Next

This section describes critical steps you must perform before installing or upgrading the Endpoint Security (HX) xAgent software on your host endpoints.

If your third-party antivirus software does not allow you to whitelist or exclude xAgent files or processes until they are present on your host endpoint, perform these steps immediately after installing or upgrading the xAgent software on your host endpoint.

Excluding xAgent files in your antivirus software

Third-party antivirus software packages use advanced heuristics engines to evaluate and protect your host endpoints. To ensure that Endpoint Security (HX) xAgent processes are not subject to these heuristics, verify that the agent executable files (*.exe files) meet the following requirements for the following antivirus software vendors (if applicable in your environment):

  • List xAgent executable files as low-risk processes in McAfee.

  • Exclude xAgent executable files from behavior monitoring in Trend Micro Office Scan.

  • Apply application exclusion to xAgent executable files in Symantec Endpoint Protection.

For more information, refer to the documentation provided with your antivirus software.

Rarely, third-party security software identifies installed Endpoint Security (HX) xAgent files and activity as malicious. It is a good idea to whitelist or exclude xAgent files from real-time scanning and behavioral analysis (sometimes known as HIPS) in your third-party security software. Endpoint Security (HX) xAgent software version 27 or later supports whitelisting by the original filename, which ensures that whitelisted files remain on the excluded list even if a user changes the filename. Endpoint Security (HX) xAgent software version 30 or later supports whitelisting by actor-based process, which allows you to suppress alerts for short lived processes.

Note

Be sure to exclude the xagt.exe file as a process in addition to excluding it as a file.

In addition,Trellix strongly recommends that you create malware protection process, file and folder exclusions for any third-party antivirus software. For example, if you are running McAfee antivirus software on your host endpoints, you should use the Malware Protection tab to create exclusions for McAfee processes, files, and folders.

Be sure to create malware protection process, file, and folder exclusions for the following third-party antivirus software running on your host endpoints:

This will maximize performance, ensure compatibility with other antivirus software, and reduce the number of duplicate alerts you receive from the Endpoint Security (HX) xAgent malware protection feature and your third-party antivirus software. Use the malware protection global policy to define these exclusions. See Defining the Malware Protection Exclusion Policy  for more information.

Excluding xAgent files for your windows environment

In your Windows environment, whitelist the directories and file paths listed in this section to exclude specific Endpoint Security (HX) xAgent program files, plug-in files, driver files, and log files from real-time scanning and behavioral analysis by your third-party antivirus software. The default directory paths and file paths, including the supported Windows version, are shown for each directory and file.

Important

If the TARGETDIR option was used with the Windows MSI to change the installation location of the xAgent software, then the exclusion path must change. For example, if TARGETDIR = C:\MyInstallationDirectory then C:\MyInstallationDirectory\*.* should be excluded instead of %ProgramFiles(x86)%\FireEye\xagt\*.* or %ProgramFiles%\FireEye\xagt\*.*.

Note

If the Endpoint Security (HX) xAgent is installed in an environment where Sophos Antivirus and the Microsoft Enhanced Mitigation Experience Toolkit (EMET) are installed, you might experience Microsoft Internet Explorer crashes. To resolve this problem, start up the EMET GUI and turn off the ROP Caller Check setting for the iexplore.exe application. Refer to the EMET documentation for more information.

Caution

Endpoint Security (HX) xAgent does not support extended file paths in a Windows environment. For more information, please see the Microsoft documentation.

Program Files Excluded

Default File Path

Windows Version

audits.dll, mindexer.sys, and xagt.exe

%ProgramFiles%\FireEye\xagt\*.*

32-bit

%ProgramFiles(x86)%\FireEye\xagt\*.*

64-bit

32-bit = 32-bit versions of Windows

64-bit = 64-bit versions of Windows

Driver Files

Default File Path

Windows Version

FeKern.sys

%SystemRoot%\System32\drivers\FeKern.sys

All

FeElam.sys

%SystemRoot%\System32\drivers\FeElam.sys

All

fe_avk.sys

%ProgramData%\FireEye\xagt\exts\MalwareProtection\

sandbox\fe_avk.sys

64-bit

64-bit = 64-bit versions of Windows

All = See "Operating System Requirements" in the Endpoint Security Agent (HX) Deployment Guide for a list of all of the supported Windows operating system versions.

All Data Files

Default File Path

Windows Version

Everything in the ProgramData\FireEye\xagt directory

%ALLUSERSPROFILE%\ApplicationData\

FireEye\xagt\*.*

NT 5.x

%ProgramData%\FireEye\xagt\*.*

NT 6+

NT 5.x = Windows XP SP3 and Windows Server 2003 SP2+R2

NT 6+ = All other supported Windows versions

Plug-In File

Default File Path

Windows Version

xagtnotif.exe

%SystemRoot%\FireEye\xagtnotif.exe

All

Any extensions in %ALLUSERSPROFILE%\ApplicationData\FireEye\xagt\exts directories or subdirectories should be whitelisted in your antivirus software.

All

All = All supported versions of Windows

Excluding xAgent files for your macOS environment

In your macOS environment, whitelist the program files, plug-in files, driver files, and log files listed in the tables below. The default file path and the supported macOS version are shown for each file.

Program Files

Default File Path

xagt/*

/Library/FireEye/xagt/*

Support/FireEye/*

/Library/Application Support/FireEye/*

com.fireeye.xagt.plist

/Library/LaunchDaemons/com.fireeye.xagt.plist

com.fireeye.xagtnotif.plist

/Library/LaunchAgents/com.fireeye.xagtnotif.plist

Excluding xAgent files for your linux environment

In your Linux environment, whitelist the program files and directories listed in the table below. The default file path and the supported Linux version are shown for each file.

Program Files

Default File Path

Linux Version

Everything in the /var/lib/fireeye/ directory

/var/lib/fireeye/*

All

Everything in the /opt/FireEye/ directory

/opt/fireeye/*

All

xagt.service

/usr/lib/systemd/system/xagt.service

RHEL 7.x

All = See "Operating System Requirements" in the Endpoint Security Agent (HX) Deployment Guide for a list of all of the supported Linux operating system versions.

Excluding Exploit Guard files in your Windows environment

In addition, if you intend to enable Exploit Guard in your Windows environment, whitelist the driver files and log files in the tables below. The default file path and the supported Windows version are shown for each file.

Note

The Exploit Guard plug-in files you need to whitelist are included in the %ALLUSERSPROFILE%\Application Data\FireEye\ xagt\*.* and %ProgramData%\FireEye\xagt\*.* directory exclusions you whitelisted in Excluding Agent Files for Your Windows Environment.

Driver Files

Default File Path

Windows Version

AppMonitorDll.dll

%SystemRoot%\FireEye\AppMonitorDll.dll

64-bit

JavaAgentDll32_xx.dll

%SystemRoot%\FireEye\JavaAgentDll32_xx.dll

(where xx is a series of incrementing numbers)

64-bit

AppUIMonitor_xx.exe

%SystemRoot%\FireEye\AppUIMonitor_xx.exe

(where xx is a series of incrementing numbers)

All

AppMonitorDll.dll

%SystemRoot%\FireEye\AppMonitorDll.dll

All

JavaAgentDll_xx.dll

%SystemRoot%\FireEye\JavaAgentDll_xx.dll

(where xx is a series of incrementing numbers)

All

64-bit = 64-bit versions of Windows

All = All supported versions of Windows

Whitelisting the xAgent process ID

You must whitelist the xAgent process ID to allow traffic from any contained Windows xAgent , and any contained macOS xAgent version 30 and later, that uses a proxy server to communicate with the Endpoint Security (HX) Server version 4.8 and later.

You must whitelist the xAgent process ID to allow traffic from any contained Linux agent version 34 and later that uses a proxy server to communicate with the Endpoint Security (HX) Server version 5.2 and later.

Note

: Host containment over proxy support is provided for Windows and macOS endpoints only.

Certificate-based whitelisting

Endpoint Security (HX) supports certificate-based whitelisting for malware alerts only. This means that you can specify a family of binaries with a single rule. Certificate-based whitelisting can be provided through the Dynamic Threat Intelligence (DTI) Portal, or you can mark an alert as false positive, selecting the Digital Signature condition. This will identify all alerts with this certificate as false positive.

Note

Trellix Endpoint Security (HX) xAgent version 27 or later supports certificate-based whitelisting for malware alerts only.