By default, when exploit prevention is enabled, it is enabled for all host sets that are running version 22 or later of the xAgent software. You can disable exploit prevention for selected host sets using the Web UI or the API.
You can create a custom policy using the Web UI or the API that excludes selected host sets from malware protection processing. Host sets that are excluded malware detection (Signature and Heuristic Detection) are also excluded from MalwareGuard, quarantine, and remediation.
Note
Trellix does not recommend excluding host sets from exploit prevention because it restricts the hosts that Exploit Guard protects.
The Exploit Guard global policy is supported on hosts using Endpoint Security (HX) xAgent version 22 or later.
To exclude all host sets from Exploit Guard processing:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link to access the Edit Policy page.
Select the Exploit Guard tab.
In the section Turn off Exploit Guard prevention actions for the selected host sets, select the host sets to exclude from exploit prevention.
Note
You cannot exclude the All Hosts set.
This global policy is ignored for hosts using version 21 (or earlier) agents.
Click Save.
To exclude selected host sets from Exploit Guard processing:
Note
See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Exploit Guard tab.
In the section Turn off Exploit Guard prevention actions for the selected host sets, select the host sets to exclude from exploit prevention.
Note
You cannot exclude the All Hosts set.
This global policy is ignored for hosts using version 21 (or earlier) agents.
Click Save.