Excluding files and folders from Exploit Guard processing

Prev Next

You can exclude a list of executable files and folders from Exploit Guard processing for all your host endpoints or selected host sets in your environment. Exploit Guard still monitors your excluded files and folders, but you will not receive an alert if an exploit occurs on an excluded file or folder. In addition, Exploit Guard activities, including application termination, do not occur on the excluded file or folder.

Important

Exploit Guard file and folder exclusions are supported on Windows agents version 22 and later only.

Excluding files and folders from Exploit Guard processing is not recommended because it restricts the items that Exploit Guard protects.

Exploit Guard file and folder exclusions defined in this section apply to all host endpoints in your enterprise except for host endpoints assigned to a custom policy that includes an Exploit Guard policy.

This section covers how to use the Web UI to manage a file and folder exclusion list for Exploit Guard processing. See the Endpoint Security (HX) REST API Guide for more information about managing Exploit Guard file and folder exclusions.