Defining the Real-TimeIndicator Detection exclusion policy

Prev Next

You may need to exclude specific files, folders, processes, and registry keys from real-time event monitoring for all of your host endpoints or selected host sets in your environment. You can use the Web UI or the API to define any of the following Exploit Guard policy exclusions:

Important

Excluding host sets, files and folders, processes, or registry keys from real-time event monitoring is not recommended because it restricts the items Real-Time monitoring detects.

Real-time event monitoring file, folder, process, or registry key exclusions defined in the agent default policy do not apply to host sets assigned to a custom policy if the custom policy defines different real-time indicator detection policy settings. To exclude files, folders, processes, and registry keys for third-party antivirus software installed on your host endpoints, you must define these exclusions for all policies that include a real-time indicator detection policy.

Prerequisites
  • Admin access when using the Web UI

  • Endpoint Security (HX) xAgent version 20 or later installed on your Windows or macOS endpoints, or xAgent version 30.19 on your Linux endpoints. If an xAgent for an earlier release is included in a host set that is managed by a policy, the policy is ignored for that xAgent .

This section covers how to use the Web UI to review, add, and remove file, folder, and process exclusions from real-time event monitoring. For more details, see the Endpoint Security APIs page on the Trellix Developer Hub.