You can enable and disable Exploit Guard processing (exploit detection and prevention) for all of your host sets using the xAgentdefault policy. You can also enable and disable Exploit Guard processing for specific host sets in your environment using a custom exclusion policy. When Exploit Guard is disabled, other Exploit Guard policy settings are ignored.
This section covers how to use the Web UI to enable and disable Exploit Guard. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your Exploit Guard policies.
If you want to enable exploit detection but do not want enable exploit prevention, enable Exploit Guard as described in this section and then see Enabling and Disabling Exploit Prevention to disable exploit prevention.
Important
A false positive is reported by exploit detection running on host endpoints that use Spoon application virtualization software.
Enabling Exploit Guard
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to go to the Edit Policy page.
Select the Exploit Guard Protection tab.
Toggle the Exploit Guard switch ON to enable Exploit Guard.
.png)
Click Save.
To enable Exploit Guard processing for selected host sets:
Note
See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Exploit Guard Protection tab.
Toggle the Exploit Guard switch ON to enable Exploit Guard.
.png)
Click Save.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.
Disabling Exploit Guard
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to go to the Edit Policy page.
Select the Exploit Guard Protection tab.
Toggle the Exploit Guard switch OFF to disable Exploit Guard.
.png)
Click Save.
To disable Exploit Guard processing for select host sets.
Note
When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Exploit Guard Protection tab.
Toggle the Exploit Guard switch OFF to disable Exploit Guard.
.png)
Click Save.