IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Anti-Virus Exclusions for Agent (Windows)

App Control: Anti-Virus Exclusions for Agent (Windows)

Environment

  • App Control Agent: All Supported Versions
  • Microsoft Windows: All Supported Versions

Objective

This document contains the list of both files and folders that should be excluded in any other security software on endpoints that also have an App Control Agent installed.

Resolution

File Exclusions:
  • C:\Windows\System32\drivers\Parity.sys
  • C:\Program Files\Bit9\Parity Agent\Crawler.exe
  • C:\Program Files\Bit9\Parity Agent\Dascli.exe
  • C:\Program Files\Bit9\Parity Agent\Notifier.exe
  • C:\Program Files\Bit9\Parity Agent\Parity.exe
  • C:\Program Files\Bit9\Parity Agent\Timedoverride.exe
  • C:\Program Files (x86)\Bit9\Parity Agent\Crawler.exe
  • C:\Program Files (x86)\Bit9\Parity Agent\Dascli.exe
  • C:\Program Files (x86)\Bit9\Parity Agent\Notifier.exe
  • C:\Program Files (x86)\Bit9\Parity Agent\Parity.exe
  • C:\Program Files (x86)\Bit9\Parity Agent\Timedoverride.exe
Folder Exclusions:
  • C:\Documents and Settings\All users\Application Data\Bit9\Parity Agent\
  • C:\ProgramData\Bit9\Parity Agent\
  • C:\Program Files\Bit9\Parity Agent\
  • C:\Program Files (x86)\Bit9\Parity Agent\

Additional Notes

  • Windows Defender is enabled by default on Windows machines, and also requires these exclusions.
  • Some vendors require a trailing asterisks (*) when entering exclusions. Sub-folders should be included on the exclusion. Please refer to the vendor's documentation.
  • The App Control Agent is considered a "real-time" scanner. It also has a self-protection mechanism (Tamper Protection) to ensure that the average end-user cannot disable it. It is important to set up an exclusion policy with your antivirus (or any other real-time scanning application) to provide proper interoperability.
  • This exclusion will also eliminate potential performance issues caused by the AV process constantly scanning our cache and transaction log files. Since we are a real-time scanner, these files are constantly being written to.

Related Content


Labels (1)
Was this article helpful? Yes No
67% helpful (6/9)
Article Information
Author:
Creation Date:
‎09-13-2018
Views:
30346
Contributors