If Exploit Prevention blocks a trusted program, you can add an exclusion for the process name. For Buffer Overflow and Illegal API Use, you can also exclude by caller module, API or signature ID. For Network IPS, you can exclude by signature ID or IP address. For Services, you can exclude by service name. For Files- Processes – Registry, you can exclude by signature ID.
Note
Exploit Prevention is not supported in the ARM architecture.
Upgrade to the latest version of endpoint security to exclude Files- Processes – Registry by signature ID. Otherwise, the exclusion gets added to the global exclusion list.
Task
Open the Trellix Endpoint Security (ENS) Client.
Click Threat Prevention on the main Status page.
Or, from the Action menu
, select Settings, then click Threat Prevention on the Settings page.Click Show Advanced.
Click Exploit Prevention.
Perform one of the following:
To...
Do this...
Exclude items from all rules.
In the Exclusions section, click Add to add items to exclude from all rules.
On the Add Exclusion page, , select the exclusion type, then configure the exclusion properties.
Click Save, then click Apply to save the settings.
Specify processes for inclusion or exclusion in a user-defined Application Protection rule. (Buffer overflow and illegal API violations only)
Edit an existing user-defined rule or add an Application Protection rule.
On the Add Rule or Edit Rule page, in the Executables section, click Add to add executables to exclude or include.
On the Add Executable page, configure the executable properties.
Click Save twice, then click Apply to save the settings.