This section describes critical steps you must perform before installing or upgrading the Endpoint Security (HX) xAgent software on your host endpoints.
If your third-party antivirus software does not allow you to whitelist or exclude xAgent files or processes until they are present on your host endpoint, perform these steps immediately after installing or upgrading the xAgent software on your host endpoint.
Excluding xAgent files in your antivirus software
Third-party antivirus software packages use advanced heuristics engines to evaluate and protect your host endpoints. To ensure that Endpoint Security (HX) xAgent processes are not subject to these heuristics, verify that the agent executable files (*.exe files) meet the following requirements for the following antivirus software vendors (if applicable in your environment):
List xAgent executable files as low-risk processes in McAfee.
Exclude xAgent executable files from behavior monitoring in Trend Micro Office Scan.
Apply application exclusion to xAgent executable files in Symantec Endpoint Protection.
For more information, refer to the documentation provided with your antivirus software.
Rarely, third-party security software identifies installed Endpoint Security (HX) xAgent files and activity as malicious. It is a good idea to whitelist or exclude xAgent files from real-time scanning and behavioral analysis (sometimes known as HIPS) in your third-party security software. Endpoint Security (HX) xAgent software version 27 or later supports whitelisting by the original filename, which ensures that whitelisted files remain on the excluded list even if a user changes the filename. Endpoint Security (HX) xAgent software version 30 or later supports whitelisting by actor-based process, which allows you to suppress alerts for short lived processes.
Note
Be sure to exclude the xagt.exe file as a process in addition to excluding it as a file.
In addition,Trellix strongly recommends that you create malware protection process, file and folder exclusions for any third-party antivirus software. For example, if you are running McAfee antivirus software on your host endpoints, you should use the Malware Protection tab to create exclusions for McAfee processes, files, and folders.
Be sure to create malware protection process, file, and folder exclusions for the following third-party antivirus software running on your host endpoints:
McAfee
Symantec Endpoint Protection (SEP)
Trend Micro Office Scan
Windows Antivirus software
Important
See Microsoft Anti-Virus Exclusion List and Running Windows Antivirus Software on Exchange 2016 Servers for more information on the folders, processes, and file name extensions you should exclude from Trellix Endpoint Security (HX) xAgent malware protection processing.
This will maximize performance, ensure compatibility with other antivirus software, and reduce the number of duplicate alerts you receive from the Endpoint Security (HX) xAgent malware protection feature and your third-party antivirus software. Use the malware protection global policy to define these exclusions. See Defining the Malware Protection Exclusion Policy for more information.
Excluding xAgent files for your windows environment
In your Windows environment, whitelist the directories and file paths listed in this section to exclude specific Endpoint Security (HX) xAgent program files, plug-in files, driver files, and log files from real-time scanning and behavioral analysis by your third-party antivirus software. The default directory paths (wildcard) and file paths, including the supported Windows version, are shown for each directory and file.
Important
If the TARGETDIR option was used with the Windows MSI to change the installation location of the xAgent software, then the exclusion path must change. For example, if TARGETDIR = C:\MyInstallationDirectory then C:\MyInstallationDirectory\*.* should be excluded instead of %ProgramFiles(x86)%\FireEye\xagt\*.* or %ProgramFiles%\FireEye\xagt\*.*.
Note
If the Endpoint Security (HX) xAgent is installed in an environment where Sophos Antivirus and the Microsoft Enhanced Mitigation Experience Toolkit (EMET) are installed, you might experience Microsoft Internet Explorer crashes. To resolve this problem, start up the EMET GUI and turn off the ROP Caller Check setting for the iexplore.exe application. Refer to the EMET documentation for more information.
Program Files Excluded | Default File Path | Windows Version |
|---|---|---|
audits.dll, mindexer.sys, and xagt.exe | %ProgramFiles%\FireEye\xagt\*.* | 32-bit |
%ProgramFiles(x86)%\FireEye\xagt\*.* | 64-bit | |
32-bit = 32-bit versions of Windows 64-bit = 64-bit versions of Windows | ||
Driver Files | Default File Path | Windows Version |
|---|---|---|
FeKern.sys | %SystemRoot%\System32\drivers\FeKern.sys | All |
FeElam.sys | %SystemRoot%\System32\drivers\FeElam.sys | All |
fe_avk.sys | %ProgramData%\FireEye\xagt\exts\MalwareProtection\ sandbox\fe_avk.sys | 64-bit |
64-bit = 64-bit versions of Windows All = See "Operating System Requirements" in the Endpoint Security Agent (HX) Deployment Guide for a list of all of the supported Windows operating system versions. | ||
All Data Files | Default File Path | Windows Version |
|---|---|---|
Everything in the | %ALLUSERSPROFILE%\ApplicationData\ FireEye\xagt\*.* | NT 5.x |
%ProgramData%\FireEye\xagt\*.* | NT 6+ | |
NT 5.x = Windows XP SP3 and Windows Server 2003 SP2+R2 NT 6+ = All other supported Windows versions | ||
Plug-In File | Default File Path | Windows Version |
|---|---|---|
xagtnotif.exe | %SystemRoot%\FireEye\xagtnotif.exe | All |
Any extensions in %ALLUSERSPROFILE%\ApplicationData\FireEye\xagt\exts directories or subdirectories should be whitelisted in your antivirus software. | All | |
All = All supported versions of Windows | ||
Excluding xAgent files for your macOS environment
In your macOS environment, whitelist the program files, plug-in files, driver files, and log files listed in the tables below. The default file path and the supported macOS version are shown for each file.
Program Files | Default File Path |
|---|---|
xagt/* | /Library/FireEye/xagt/* |
Support/FireEye/* | /Library/Application Support/FireEye/* |
com.fireeye.xagt.plist | /Library/LaunchDaemons/com.fireeye.xagt.plist |
com.fireeye.xagtnotif.plist | /Library/LaunchAgents/com.fireeye.xagtnotif.plist |
Excluding xAgent files for your linux environment
In your Linux environment, whitelist the program files and directories listed in the table below. The default file path and the supported Linux version are shown for each file.
Program Files | Default File Path | Linux Version |
|---|---|---|
xagt | /etc/rc.d/init.d/xagt | RHEL 6.x |
Everything in the | /var/lib/fireeye/* | All |
Everything in the | /opt/fireeye/* | All |
xagt.service | /usr/lib/systemd/system/xagt.service | RHEL 7.x |
All = See "Operating System Requirements" in the Endpoint Security Agent (HX) Deployment Guide for a list of all of the supported Linux operating system versions. | ||
Excluding Exploit Guard files in your Windows environment
In addition, if you intend to enable Exploit Guard in your Windows environment, whitelist the driver files and log files in the tables below. The default file path and the supported Windows version are shown for each file.
Note
The Exploit Guard plug-in files you need to whitelist are included in the %ALLUSERSPROFILE%\Application Data\FireEye\ xagt\*.* and %ProgramData%\FireEye\xagt\*.* directory exclusions you whitelisted in Excluding Agent Files for Your Windows Environment.
Driver Files | Default File Path | Windows Version |
|---|---|---|
AppMonitorDll.dll | %SystemRoot%\FireEye\AppMonitorDll.dll | 64-bit |
JavaAgentDll32_xx.dll | %SystemRoot%\FireEye\JavaAgentDll32_xx.dll (where xx is a series of incrementing numbers) | 64-bit |
AppUIMonitor_xx.exe | %SystemRoot%\FireEye\AppUIMonitor_xx.exe (where xx is a series of incrementing numbers) | All |
AppMonitorDll.dll | %SystemRoot%\FireEye\AppMonitorDll.dll | All |
JavaAgentDll_xx.dll | %SystemRoot%\FireEye\JavaAgentDll_xx.dll (where xx is a series of incrementing numbers) | All |
64-bit = 64-bit versions of Windows All = All supported versions of Windows | ||
Whitelisting the xAgent process ID
You must whitelist the xAgent process ID to allow traffic from any contained Windows xAgent , and any contained macOS xAgent version 30 and later, that uses a proxy server to communicate with the Endpoint Security (HX) Server version 4.8 and later.
You must whitelist the xAgent process ID to allow traffic from any contained Linux agent version 34 and later that uses a proxy server to communicate with the Endpoint Security (HX) Server version 5.2 and later.
Note
: Host containment over proxy support is provided for Windows and macOS endpoints only.
Certificate-based whitelisting
Endpoint Security (HX) supports certificate-based whitelisting for malware alerts only. This means that you can specify a family of binaries with a single rule. Certificate-based whitelisting can be provided through the Dynamic Threat Intelligence (DTI) Portal, or you can mark an alert as false positive, selecting the Digital Signature condition. This will identify all alerts with this certificate as false positive.
Note
Trellix Endpoint Security (HX) xAgent version 27 or later supports certificate-based whitelisting for malware alerts only.