<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exclusion Questions in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/146079#M5501</link>
    <description>&lt;P&gt;Found this Thread by accident, is there an SK about this somewhere?&lt;/P&gt;&lt;P&gt;At this point i have around 200 AV Exclusions for Windows, Exchange, MSSQL, VMWare, Oracle etc...&lt;BR /&gt;What is in detail included - i'm not quite sure what to include and what not to include.&lt;BR /&gt;TAC told me quite the opposite that nothing is included by default and that it is the customers choice and that an exclude always increases the risk.&lt;BR /&gt;&lt;BR /&gt;BR Michele Evermann&lt;/P&gt;</description>
    <pubDate>Tue, 12 Apr 2022 12:27:21 GMT</pubDate>
    <dc:creator>Michi</dc:creator>
    <dc:date>2022-04-12T12:27:21Z</dc:date>
    <item>
      <title>Exclusion Questions</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/111638#M4003</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a new customer who has a few questions about exclusions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Does CheckPoint automatically exclude any files or folders to allow SBA operation?&lt;/LI&gt;&lt;LI&gt;Does CheckPoint automatically exclude any files or folders per vendor best practices?&lt;/LI&gt;&lt;LI&gt;Do exclusions in the AV blade affect EDR tracking?&lt;/LI&gt;&lt;LI&gt;How do you apply exclusions to the EDR blade?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I reviewed&amp;nbsp;&lt;SPAN&gt;sk122706 How to use Endpoint Security Client Anti-Malware Blade exclusions and&amp;nbsp;sk162553&amp;nbsp;ATRG: Endpoint Security Anti-Malware Blade and didn't find specific answers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Also, both these sk articles use SmartEndpoint. Is it recommended to use SmartEndpoint or the Infinity Portal?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 15:35:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/111638#M4003</guid>
      <dc:creator>Trey</dc:creator>
      <dc:date>2021-02-23T15:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion Questions</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/111961#M4017</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Does CheckPoint automatically exclude any files or folders to allow SBA operation? --&amp;gt; Yes there are several folders and processes that we exclude to make sure the performance impact are minimal. The processes and the folders that excluded have no security value. Keep in mind that our EDR solution monitor all file\registry\network\process\script(obfuscated and deobfuscated )\injection and more.&lt;/LI&gt;
&lt;LI&gt;Does CheckPoint automatically exclude any files or folders per vendor best practices? --&amp;gt; We exclude by default the well known vendors in case they present on the machine.&lt;/LI&gt;
&lt;LI&gt;Do exclusions in the AV blade affect EDR tracking? --&amp;gt; In case exclusion are done in Forensics blade it will effect EDR tracking.&lt;/LI&gt;
&lt;LI&gt;How do you apply exclusions to the EDR blade? --&amp;gt; By configure policy for Forensics baled.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I reviewed&amp;nbsp;&lt;SPAN&gt;sk122706 How to use Endpoint Security Client Anti-Malware Blade exclusions and&amp;nbsp;sk162553&amp;nbsp;ATRG: Endpoint Security Anti-Malware Blade and didn't find specific answers.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Also, both these sk articles use SmartEndpoint. Is it recommended to use SmartEndpoint or the Infinity Portal? --&amp;gt;&amp;nbsp;Infinity Portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--&amp;gt; For any additional questions you can contact me as well, romanzit@checkpoint.com&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Feb 2021 13:34:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/111961#M4017</guid>
      <dc:creator>Roman_Zitzev</dc:creator>
      <dc:date>2021-02-27T13:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion Questions</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/112150#M4026</link>
      <description>&lt;P&gt;What are the f&lt;SPAN&gt;olders and processes that you exclude?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does excluding by default the well known vendors mean you don't have to add, for instance, the recommended Microsoft exclusions?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 17:24:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/112150#M4026</guid>
      <dc:creator>Trey</dc:creator>
      <dc:date>2021-03-01T17:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion Questions</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/112155#M4028</link>
      <description>&lt;P&gt;What are the f&lt;SPAN&gt;olders and processes that you exclude? --&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Folders:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;1. Internal folders that used by the application that running from them or writing logs\info into them, for example chrome that write to its own folders&lt;/P&gt;
&lt;P&gt;in %programfiles% or %programdata%.&lt;/P&gt;
&lt;P&gt;this done by the signer of the application and the destination.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Processes:&lt;/P&gt;
&lt;P&gt;1. Other vendors processes like windows defender or Kaspersky, its done by the signer.&lt;/P&gt;
&lt;P&gt;2. Specific list of processes that monitor or creating large activity on the system like processes explorer, java IDE and more.&lt;/P&gt;
&lt;P&gt;its done base on the signer and name&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Does excluding by default the well known vendors mean you don't have to add, for instance, the recommended Microsoft exclusions? --&amp;gt; Correct&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if you wish we can do a short zoom session and i can explain more about our exclusion system.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 17:44:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/112155#M4028</guid>
      <dc:creator>Roman_Zitzev</dc:creator>
      <dc:date>2021-03-01T17:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion Questions</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/146079#M5501</link>
      <description>&lt;P&gt;Found this Thread by accident, is there an SK about this somewhere?&lt;/P&gt;&lt;P&gt;At this point i have around 200 AV Exclusions for Windows, Exchange, MSSQL, VMWare, Oracle etc...&lt;BR /&gt;What is in detail included - i'm not quite sure what to include and what not to include.&lt;BR /&gt;TAC told me quite the opposite that nothing is included by default and that it is the customers choice and that an exclude always increases the risk.&lt;BR /&gt;&lt;BR /&gt;BR Michele Evermann&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 12:27:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/146079#M5501</guid>
      <dc:creator>Michi</dc:creator>
      <dc:date>2022-04-12T12:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion Questions</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/146398#M5515</link>
      <description>&lt;P&gt;I think this information (which is very important) should be well explained and clear in some SK or management guide.&amp;nbsp;It is of great interest to our customers and would save us administrators hours of configuration and research to apply exceptions manually.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 12:03:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/146398#M5515</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2022-04-18T12:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Exclusion Questions</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/149744#M5699</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10184"&gt;@Roman_Zitzev&lt;/a&gt;&amp;nbsp;do you have this information published anywhere?&lt;/P&gt;&lt;P&gt;BR Michi&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 15:19:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Exclusion-Questions/m-p/149744#M5699</guid>
      <dc:creator>Michi</dc:creator>
      <dc:date>2022-05-30T15:19:34Z</dc:date>
    </item>
  </channel>
</rss>

