I am looking at the Anti-Ransomware and Behavioral Guard settings in our endpoint security policy, and noticed that there is an exclusion for C:\Windows\explorer.exe (process) along with a handful of certificate based exclusions for Symantec, TrendMicro, etc.
I don't come in here to mess with this policy setting, but I seem to recall that the certificate based exclusions are normal "out of the box" settings. I don't recall that an exclusion for the Explorer.exe process is a default though? Can anyone confirm if it is?
Thanks,
~D