IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: What processes paths should be excluded in KernelProcessExclusions for Windows Defender?

App Control: What processes paths should be excluded in KernelProcessExclusions for Windows Defender?

Environment

  • App Control Agent: All Supported Versions
  • App Control Console: All Supported Versions
  • Windows: All Supported Versions

Question

What processes paths should be used in a Kernel Exclusion for Windows Defender?

Answer

Due to a variety of environmental differences, a specific set of logs will be required to validate the paths/operations necessary:
  1. Verify Windows Defender has all Agent Exclusions entered.
  2. Collect the Agent Performance Logs.
  3. Create a ticket with Carbon Black Support.
  4. Upload the collected logs to the Vault for review.

Additional Notes

  • There must be exclusions in Windows Defender before the Kernel Exclusions are added to prevent Agent instability/corruption.
  • There are multiple versions of Windows Defender and Kernel Exclusions should only be added for paths that currently exist/are in use in the environment.

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎10-27-2021
Views:
1205
Contributors