The excludedFiles key lists the files and folders to be excluded from Exploit Guard processing. This list of files and folders is part of the Exploit Guard global policy.
There is no default. If no files or folders are listed, all files and folders are included in Exploit Guard processing.
Files and folders should be listed within quotation marks (") and separated by commas. The full list of files should be enclosed in brackets ([]). For example:
"excludedFiles": [ "\\system32\\", "\\FireEye\\xagt\\events.*" ]
Exclusion Guidelines
Follow these guidelines when adding file or folder path exclusions to the Exploit Guard exclusion list:
Change this setting using one of the following methods:
Web UI (see )
API custom configuration channels (see Using API Custom Configuration Channels).
Manually on individual endpoints using a text editor (see Modifying the Configuration File for a Single Endpoint).