The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Exclude items from Exploit Prevention protection

Prev Next

If Exploit Prevention blocks a trusted program, you can add an exclusion for the process name. For Buffer Overflow and Illegal API Use, you can also exclude by caller module, API or signature ID. For Network IPS, you can exclude by signature ID or IP address. For Services, you can exclude by service name. For Files- Processes – Registry, you can exclude by signature ID.

Task
  1. Select MenuPolicyPolicy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.

  2. From the Category list in the right pane, select Exploit Prevention.

  3. Click the Edit link for an editable policy.

  4. Click Show Advanced.

  5. Perform one of the following

    To...

    Do this...

    Exclude items from all rules.

    1. In the Exclusions section, click Add to add items to exclude from all rules.

    2. On the Exclusion page, configure the exclusion properties.

    3. Click Save twice to save the settings.

    Note

    You can also include multiple processes or directory paths within a single Exploit Prevention exclusion. This eliminates the need to create separate entries for each item

    Specify processes for inclusion or exclusion in a user-defined Application Protection rule.

    (Buffer overflow and illegal API violations only)

    1. Edit an existing user-defined rule or add an Application Protection rule.

    2. On the Application Protection Rule page, in the Executables section, click Add, then configure the executable properties.

    3. Click Save three times to save the settings.