Endpoint Security protection features, such as Self Protection and Access Protection, and other Trellix product protection rules, are enforced by a technology called Arbitrary Access Control (AAC). AAC rules protect objects, such as files, processes, and registry data, from being accessed by malware and untrusted programs.
For troubleshooting, you can temporarily exclude processes from all AAC rules by configuring a global exclusion policy setting. Use global exclusions only for specific troubleshooting and support purposes.
For example, to set up auditing on your Windows systems where specific Windows executables must have read/write access to the target directories, you can temporarily exclude those executables from the AAC rules.
Best Practice: For information about troubleshooting blocked third-party applications, see KB88482.
Considerations when specifying global exclusions
You must specify at least one identifier: Process MD5 hash or Signer certificate MD5 hash.
If you specify more than one identifier, all identifiers apply.
If you specify more than one identifier and they don't match, the exclusion is invalid. For example, the file name and MD5 hash don't apply to the same file.
Exclusions are case insensitive.
Wildcards are not allowed.