Exclusions Management
- 19 Mar 2024
- 2 Minutes to read
- Print
- DarkLight
- PDF
Exclusions Management
- Updated on 19 Mar 2024
- 2 Minutes to read
- Print
- DarkLight
- PDF
Article summary
Did you find this summary helpful?
Thank you for your feedback
About this Article
This article provides information related to Exclusion List - Global and at the Profile-level. This list can be used to define the directories or files that do not require Host Protection.
Exclusion List
Exclusion List is the list of directories and files that need to be excluded from host protection. This can be defined at the global or profile level.
- Once a file/directory is added to the exclusion list, all the current incidents related to this file/directory are automatically acknowledged. They are no longer visible as Incidents
- Both global and profile exclusion lists are considered while creating a new profile
- Normal regex syntax can be utilized to define the Exclusion List
- Instead of adding explicit spaces, it is recommended to use "[ ]+" so that one or more spaces can be matched instead of the exact number of spaces
- It is recommended that the Windows nativeimages libraries be added to the exclusion list using the regex: C:\\windows\\assembly\\nativeimages.* to avoid allowlisting each nativeimages library after incident detection
- Validate the regular expression on https://regex101.com/ before its addition on the CMS
- Some sample RegEx examples are provided in the below table:
RegEx Example | Represented Files/Directories |
---|---|
Windows | |
.:\\*test.*\\*tmp\\*.* | C:\test-1\tmp\tmp-lib.dll C:\test-2\tmp\tmp-lib-2.dll D:\test-test\tmp\tmp-lib-3.dll |
C:\\ProgramData\\Amazon\\SSM\\*.* | C:\ProgramData\Amazon\SSM\example.exe |
C:\\dir1\\tmp\\tmp-lib.dll | Specific file: C:\dir1\tmp\tmp-lib.dll |
C:\\dir1\\dir2\\*.exe | All the files with extension .exe in the directory: C:\dir1\dir2 |
C:\\dir1\\dir2\\* | All the files in the directory: C:\dir1\dir2 |
Linux | |
/opt/test/tmp.*/.* | /opt/test/tmp-1/example /opt/test/tmp-abc/example-2 |
/var/packages/.*cache.*/.* | /var/packages/pkg-cache/program-1 /var/packages/publisher-cache/program-2 |
/opt/test/tmp-1/example.sh | Specific file: /opt/test/tmp-1/example.sh |
/home/user/*.log | All the files with extension .log in the directory: /home/user |
/home/user/log/* | All the files in the directory: /home/user/log |
NOTE
[Version 3.0.0 and Above]
Whenever an entry is added to the exclusion list:
- Incidents related to it is auto-acknowledged
- Associated executables are no longer listed in the allowlist
- Associated process may remain in allowlist if there are any libraries or scripts associated with that it that are not eligible for removal
Global Exclusion List
This list is applicable to all the Host Profiles. To view or modify the Global Exclusion List, follow the below steps:
- On the Host Monitoring page, click ALL PROFILES > Exclusions List > Add Allowlist Exclusion
- In the pop-up window, add the regular expression that matches the directory path and press Enter. One entry can be added at a time.
- Once the new entry is added to the list. Click SAVE
- The added entries can be deleted if required
- Once an entry is added to the exclusion list, the allowlist is automatically optimized to remove the entries
Profile-level Exclusion List
This list is applicable to a particular Host Profiles. To view or modify this List, follow the below steps:
- On the Host Monitoring page, click Edit for the required profile. Modify as required and click SAVE
- for Versions 2.9 and Above: By default, some directories are added to both the lists – Exclusions For AllowList and Exclusions For Memory Exploit Protection. Do not alter them as that can affect normal VSP functioning
- Once an entry is added to the exclusion list, the allowlist is automatically optimized to remove the entries
Was this article helpful?