You may need to exclude specific files and folders, processes, and MD5 hashes from Malware Protection processing on all of your host endpoints or selected host sets. Use the Web UI or the API to define the following Malware Protection exclusions:
Select host sets to which the exception policy applies. See Assigning Host Sets to Agent Policies.
Exclude specific processes from malware protection processing for all host endpoints or selected host sets. See Adding Process Exclusions to Malware Protection Processing.
Exclude specific files and folders from malware protection processing for all host endpoints or selected host sets. See Adding Files and Folders Exclusions to Malware Protection Processing.
Exclude specific MD5 hashes from malware protection processing for all host endpoints or selected host sets. See Adding MD5 Hash Exclusions to Malware Protection Processing.
Important
Malware protection exclusions are supported for host endpoints running in specific Windows environments only. Malware protection exclusions are not supported for host endpoints running Windows 2003, XP, or Vista or Windows xAgent versions 23 or earlier.
Excluding host sets, processes, files and folders, or MD5 hashes from malware protection processing is not recommended because it restricts the items that malware protection scans.
Malware protection process, file and folder, or MD5 hash exclusions defined in the xAgent default policy do not apply to host sets assigned to a custom policy, if the custom policy defines different malware protection policy settings. To exclude processes and files and folders for third-party antivirus software installed on your host endpoints, you must define these exclusions for all policies that include a malware protection policy.
Admin access when using the Web UI
Endpoint Security (HX) xAgent version 22 or later installed on your Windows endpoint. If an agent for an earlier release is included in a host set that is managed by a policy, the policy is ignored for that agent.
This section covers the following topics:
Malware Protection Exclusion Guidelines
Follow these guidelines when adding files and folders, processes, and MD5 hashes to the Malware Protection exclusion list:
Adding process exclusions to malware protection processing
You can exclude a list of processes from malware protection for all of your host endpoints or for select host sets in your environment. Modify the to include a list of processes you want to exclude from malware protection for all of your host endpoints. Use a custom policy to exclude a list of processes from malware protection for select host sets in your environment.
Important
Malware protection process exclusions are supported on hosts using Trellix Endpoint Security (HX) xAgent version 24 or later only.
Excluding processes from malware protection processing is not recommended because it restricts the processes that malware protection scans.
This section covers how to use the Web UI to modify the to add or remove process exclusions from malware protection processing. See the Trellix Endpoint Security (HX) REST API Guide for more information about adding and removing process exclusions from malware protection processing.
Adding Process Exclusions to All Host Endpoints
To add process exclusions to malware protection processing for all host endpoints:
Note
Excluding processes from malware protection processing is not recommended because it restricts the processes that malware protection scans.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to access the Edit Policy page.
Select the Malware Protection tab.
In the Policy Exclusions section, specify the process you want to exclude from malware protection processing by entering the full process path or a wildcard followed by the process name in the field under the Exclude processes from malware scanning.
For example, adding
C:\Windows\Folder\executable.exeor*\executable.exeto the process exclusion list will exclude theexecutable.exeapplication from malware protection processing..png)
Click Add to add the process to the list.
Repeat Steps 5 and 6 until you have added all the processes you want to the list.
Click Save.
Adding Process Exclusions to Selected Host Sets
To add process exclusions to malware protection processing for selected host sets:
Note
NOTE: See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Caution
Trellix does not recommend adding a global wildcard variable to the process exclusion list because it can reduce security.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Malware Protection tab.
In the Policy Exclusions section, specify the process you want to exclude from malware protection processing by entering the full process path or a wildcard followed by the process name in the field under the Exclude processes from malware scanning.
For example, adding
C:\Windows\Folder\executable.exeor*\executable.exeto the process exclusion list will exclude theexecutable.exeapplication from malware protection processing..png)
Click Add to add the process to the list.
Repeat Steps 5 and 6 until you have added all the processes you want to the list.
Click Save.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.
Removing Process Exclusions from Malware Protection Processing
You can remove process exclusions from a malware protection policy assigned to all of your host endpoints or selected host sets using the Web UI or the API.
This section covers the steps for removing process exclusions from a malware protection policy using the Web UI. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your malware protection process exclusions.
Removing Process Exclusions for All Host Endpoints
To remove process exclusions from malware protection processing for all host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to access the Edit Policy page.
Select the Malware Protection tab.
In the Policy Exclusions section, select the process you want to remove from the list below the Exclude processes from malware scanning option.
Click the
icon next to the process you want to remove from the list.Repeat Steps 5 and 6 until you have removed all the processes you want to delete from the list.
Click Save.
Removing Process Exclusions from Selected Host Sets
To remove process exclusions from malware protection processing for selected host sets:
Note
When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Malware Protection tab.
In the Policy Exclusions section, select the process you want to remove from the list below the Exclude processes from malware scanning option.
Click the
icon next to the process you want to remove from the list.Repeat Steps 5 and 6 until you have removed all the processes you want to delete from the list.
Click Save.
Adding files and folders exclusions to malware protection processing
You can use the Web UI or the API to add a list of file and folder exclusions to malware protection processing Modify the to add a list of file and folder exclusions for all of your host endpoints. Modify your custom policies to add a list of file and folder exclusions for select host sets in your environment.
Important
File and folder exclusions are supported on hosts using Endpoint Security (HX) xAgent version 24 or later only.
Excluding files or folders from malware protection processing is not recommended because it restricts the files and folders that malware scans.
Follow these guidelines when adding file or folder paths to the Malware Protection exclusion list:
This section covers how to use the Web UI to modify the to add or remove file and folder exclusions from malware protection processing.
Adding File and Folder Exclusions for All Endpoints
To add file and folder exclusions to malware protection processing for all host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to access the Edit Policy page.
Select the Malware Protection tab.
In the Policy Exclusions section, specify the file path for the file or folder you want to exclude from malware protection processing in the field under the Exclude files or folders from malware scanning.
Click Add to add the files and folders to the list.
Repeat Steps 5 and 6 until you have added all the files and folders you want to the list.
Click Save.
Adding File and Folder Exclusions for Selected Host Sets
To add file and folder exclusions to malware protection processing for selected host sets:
Note
See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Malware Protection tab.
In the Policy Exclusions section, specify the file path for the file or folder you want to exclude from malware protection processing in the field under the Exclude files or folders from malware scanning.
Click Add to add the files and folders to the list.
Repeat Steps 5 and 6 until you have added all the files and folders you want to the list.
Click Save.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.
Removing Files and Folder Exclusions from Malware Protection Processing
You can remove file and folder exclusions from a malware protection policy assigned to all of your host endpoints or selected host sets using the Web UI or the API.
This section covers the steps for removing file and folder exclusions from a malware protection policy using the Web UI. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your malware protection process exclusions.
Removing File and Folder Exclusions for All Endpoints
To remove files and folders exclusions from malware protection processing for all host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to access the Edit Policy page.
Select the Malware Protection tab.
In the Policy Exclusions section, locate the file or folder you want to remove from the list below the Exclude files and folders from malware scanning option.
Click the
icon next to the file or folder to remove it from the list.Repeat Step 5 until you have removed all the files or folders you want from the list.
Click Save.
Removing File and Folder Exclusions for Selected Host Sets
To remove files and folders exclusions from malware protection processing for selected host sets:
Note
When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Malware Protection tab.
In the Policy Exclusions section, locate the file or folder you want to remove from the list below the Exclude files and folders from malware scanning option.
Click the
icon next to the file or folder to remove it from the list.Repeat Step 5 until you have removed all the files or folders you want from the list.
Click Save.
Adding MD5 hash exclusions to malware protection processing
You can add a list of MD5 hashes you wan to exclude from malware protection processing for all of your host endpoints or select host sets in your environment using the Web UI or the API.
MD5 hash exclusion is only supported on hosts using Trellix Endpoint Security (HX) xAgent version 24 or later.
This section covers the steps for adding MD5 hash exclusions from a malware protection policy using the Web UI. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your malware protection process exclusions.
Important
Excluding MD5 hashes from malware protection processing is not recommended because it restricts the hashes that malware protection scans.
Adding MD5 Hash Exclusions for All Host Endpoints
MD5 hash exclusions are excluded from malware protection processing (both malware detection and prevention) for host set assigned to the or the custom policy that includes an MD5 hash exclusion list.
Important
The Endpoint Security (HX) server does not validate the MD5 hash entries included in your Malware Protection exclusion list. You must confirm your MD5 hash exclusions are represented by 32 hexadecimal digits.
To add MD5 hash exclusions to malware protection for all host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to access the Edit Policy page.
Select the Malware Protection tab.
In the Policy Exclusions section, specify the MD5 hash you want to exclude from malware protection processing in the field under the Exclude hashes from malware scanning.
.png)
Click Add to add the MD5 hash to the list.
Repeat Steps 5 and 6 until you have added all of the MD5 hash exclusions you want to the list.
Click Save.
Adding MD5 Hash Exclusions for Selected Host Sets
To add MD5 hash exclusions to malware protection processing for selected host sets:
Note
NOTE: See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Important
The Endpoint Security (HX) server does not validate the MD5 hash entries included in your Malware Protection exclusion list. You must confirm your MD5 hash exclusions are represented by 32 hexadecimal digits.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link to the custom policy you want to modify.
Select the Malware Protection tab.
In the Policy Exclusions section, specify the MD5 hash you want to exclude from malware protection processing in the field under the Exclude hashes from malware scanning.
.png)
Click Add to add the MD5 hash to the list.
Repeat Steps 5 and 6 until you have added all of the MD5 hash exclusions you want to the list.
Click Save.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.
Removing MD5 Hash Exclusions from Malware Protection Processing
You can remove MD5 hash exclusions from a malware protection policy assigned to all of your host endpoints or selected host sets using the Web UI or the API.
This section covers the steps for removing MD5 hash exclusions from a malware protection policy using the Web UI. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your malware protection process exclusions.
Removing MD5 Hash Exclusions from All Host Endpoints
To remove MD5 hash exclusions from malware detection processing for all host endpoints:
Note
Excluding MD5 hashes from malware protection processing is not recommended because it restricts the hashes that malware protection scans.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to access the Edit Policy page.
Select the Malware Protection tab.
In the Policy Exclusions section, locate the MD5 hash you want to remove from the list below the Exclude hashes from malware scanning option.
Click the
icon next to the MD5 hash you want to remove it from the list.Repeat Step 5 until you have removed all of the MD5 hash exclusions you want from the list.
Click Save.
Removing MD5 Hash Exclusions from Selected Host
To remove MD5 hashes exclusions from malware protection for selected host sets:
Note
When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Malware Protection tab.
In the Policy Exclusions section, locate the MD5 hash you want to remove from the list below the Exclude hashes from malware scanning option.
Click the
icon next to the MD5 hash to remove it from the list.Repeat Step 5 until you have removed all the MD5 hash exclusions you want from the list.
Click Save.