Defining exploit guard protection exclusion policies

Prev Next

You may need to exclude specific files and folders, monitored applications (processes), and MD5 hashes from Exploit Guard processing on all of your host endpoints or selected host sets. You can use the Web UI or the API to define any of the following Exploit Guard policy exclusions:

  • Exclude all host sets or selected host sets from Exploit Guard processing, including both Exploit Guard detection and Exploit Guard prevention processing.

  • Exclude all host sets or selected host sets from Exploit Guard prevention processing only.

  • Exclude specific processes from Exploit Guard processing for all host endpoints or selected host sets.

  • Exclude specific file executables from Exploit Guard processing for all host endpoints or selected host sets.

  • Exclude specific MD5 hashes from Exploit Guard processing for all host endpoints or selected host sets.

Important

Exploit Guard process, file, folder, and MD5 hash exclusions are supported on Windows agents version 22 and later only.

Excluding host sets, processes, files and folders, or MD5 hashes from Exploit Guard processing is not recommended because it restricts the items that Exploit Guard protects.

Exploit Guard file, folder, or process exclusions defined in the xAgent default policy do not apply to host sets assigned to a custom policy, if the custom policy defines different Exploit Guard policy settings. To exclude files, folders, and processes for third-party antivirus software installed on your host endpoints, you must define these exclusions for all policies that include an Exploit Guard policy.

Prerequisites

  • Admin access when using the Web UI

  • Endpoint Security (HX) xAgent version 22 or later installed on your Windows endpoint. If an xAgent for an earlier xAgent version is included in a host set that is managed by a policy, the policy is ignored for that xAgent .

This section covers the following topics: