If Exploit Prevention blocks a trusted program, you can add an exclusion for the process name. For Buffer Overflow and Illegal API Use, you can also exclude by caller module, API or signature ID. For Network IPS, you can exclude by signature ID or IP address. For Services, you can exclude by service name. For Files- Processes – Registry, you can exclude by signature ID.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Threat Prevention from the Products list in the left pane.
From the Category list in the right pane, select Exploit Prevention.
Click the Edit link for an editable policy.
Click Show Advanced.
Perform one of the following
To...
Do this...
Exclude items from all rules.
In the Exclusions section, click Add to add items to exclude from all rules.
On the Exclusion page, configure the exclusion properties.
Click Save twice to save the settings.
Note
You can also include multiple processes or directory paths within a single Exploit Prevention exclusion. This eliminates the need to create separate entries for each item
Specify processes for inclusion or exclusion in a user-defined Application Protection rule.
(Buffer overflow and illegal API violations only)
Edit an existing user-defined rule or add an Application Protection rule.
On the Application Protection Rule page, in the Executables section, click Add, then configure the executable properties.
Click Save three times to save the settings.