By default, when Exploit Guard processing (exploit detection and exploit prevention) is enabled, it is enabled for all host sets that are running a version of the xAgent software that supports the associated Exploit Guard components (version 21 or later for exploit detection and version 22 or later for exploit prevention). You can create a custom policy in the Web UI or the API that excludes selected host sets from Exploit Guard processing.
Note
Excluding host sets from Exploit Guard processing is not recommended because it restricts the host endpoints that Exploit Guard protects.
This section covers how to use the Web UI to create a custom policy that excludes host sets from Exploit Guard processing.
To exclude selected host sets from Exploit Guard processing:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
Click Create Custom Policy to go to the Create Policy page.
Enter a policy name in the Name field and a policy description in the Description field.
Click Categories to access a list of the policy categories.
Select the Exploit Guard checkbox and click Apply.
Toggle the Exploit Guard switch OFF to disable Exploit Guard.
.png)
Click Save.
After you create a custom policy that disables Exploit Guard processing, you can use the steps outlined in Assigning Host Sets to Agent Policies to assign specific host sets to your custom policy. This will disable Exploit Guard processing for all of the selected host sets.