Excluding MD5 hashes from Exploit Guard processing

Prev Next

You can add and remove a list of excluded MD5 hashes in the Exploit Guard global policy using the Web UI or the API.

Excluding an MD5 hash from Exploit Guard processing does not prevent Exploit Guard from monitoring the MD5 hash. Monitoring still occurs but you will not receive any alerts or other Exploit Guard activities, including application termination, if an exploit does occur for the excluded MD5 hash.

Important

Exploit Guard MD5 hash exclusions are supported on Windows agents version 22 or later only.

Excluding MD5 hashes from Exploit Guard processing is not recommended because it restricts the MD5 hashes that Exploit Guard protects.

Exploit Guard MD5 hash exclusions defined in this section apply to all host endpoints in your enterprise except for host endpoints assigned to a custom policy that includes an Exploit Guard policy.

This section covers how to use the Web UI to manage an MD5 hash exclusion list for Exploit Guard processing. See the Endpoint Security (HX) REST API Guide for more information about managing MD5 hash exclusions.