You can add and remove a list of monitored applications (processes) that you want to exclude from Exploit Guard processing. Excluding an application for Exploit Guard processing prevents Exploit Guard from monitoring the application or performing other Exploit Guard activities, including application termination. If an exploit occurs on the excluded application, you will not receive an alert.
Applications that are monitored for exploits are Adobe Reader, Adobe Flash, Internet Explorer, Firefox, Google Chrome, Java, Microsoft Outlook, Microsoft Word, Microsoft Excel, Microsoft PowerPoint, and Microsoft Office 2010 files.
Important
Exploit Guard monitored application exclusions are supported on Windows agents version 22 and later only.
Excluding monitored applications from Exploit Guard processing is not recommended because it restricts the monitored applications that Exploit Guard protects.
Exploit Guard process exclusions defined in the apply to all host endpoints in your enterprise except for host endpoints assigned to a custom policy that includes an Exploit Guard policy.
This section covers how to use the Web UI to manage a monitored applications list for Exploit Guard processing. See the Endpoint Security (HX) REST API Guide for more information about managing monitored application exclusions using the API.