Jump to content

Detection exclusions for a folder


Misza

Recommended Posts

As in the title, is it possible to create an detection exclusion for a folder and its subfolders?

In ESET Protect console so far I can see I can create an exclusion from an already triggered event.

Is it possible to create an exclusion from a scratch?

And specify that any detections within a specific folder and its subfolders to be ignored?

Link to comment
Share on other sites

  • Administrators

You can create only a performance exclusion from the ESET PROTECT console before a detection is triggered.

Also detection exclusions for a folder can be created only in Endpoint. It is not possible to create such from ESET PROTECT if you want to limit it only to a specific folder.

Link to comment
Share on other sites

Hi Marcos, thank you for your reply.

I thought having to remote onto a pc and setting these could have been avoided, as I have a good few computers to cover.

That's a pity. I assume there is no way to automate this in any way?

Link to comment
Share on other sites

  • Administrators

Could you please elaborate more on the use case? Do you want a particular detection not to be triggered on files in a certain folder but in other folders the files should be detected?

Link to comment
Share on other sites

Hi Marcos,

that is somewhat correct, more precisely I don't want any detections to be triggered on files in a certain folder.

So this folder is completely whitelisted, and skipped by the detections module completely.

There is a bit of software that uses this folder and whenever it receives an update this triggers the detection engine.

Each time an update is received its unpacked to this folder, the hash and file name differ each time a new update is unpacked in that folder. so I cant really exclude it by name or hash. Therefore was looking how to whitelist the whole folder.

Detections are triggered with a cause:

Win32/RiskWare.nameofprogram 

or with 

Suspicious

Hope this makes sense, I can provide more info if needed.

* edited some typos

Edited by Misza
Link to comment
Share on other sites

  • Administrators

If you don't want any detection to be triggered on files in the folder, create a performance exclusion via a policy.

Link to comment
Share on other sites

Hi Marcus,

Did just that, yet the errors still pop up. Is my understanding correct that performance exclusions via policy will 

only exclude for the scan purposes and  detection exclusion is a separate thing?

Link to comment
Share on other sites

Have the performance exclusion set to C:\ProgramData\{program_name}\*

so my assumption was anything within {program_name} including subfolders will be excluded.

Policy applied to the endpoint, unless I need to give it a higher priority. But there is nothing above it in the policy order which would negate it.

 

Link to comment
Share on other sites

  • Administrators

Yes, the above performance exclusion should work unless overridden by another policy that replaces the exclusion list.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...