Threat Emulation -> Anti-Exploit Exclusions

You can exclude these elements from the Anti-Exploit protection:

  • Protection Name - Predefined malware signature

  • Process - To exclude an executable

Currently there are five different Anti-Exploit protections available. Following is a list of the protections per-name.

Syntax for exclusions:

Protection

Protection Rule Name

Import-Export Address Table Parsing

Gen.Exploiter.IET

Return Oriented Programming

Gen.Exploiter.ROP

VB Script God Mode

Gen.Exploiter.VBS

Stack Pivoting

Gen.Exploiter.SP

RDP Vulnerability (CVE-2019-0708)

Gen.Exploiter.CVE_2019_0708

RCE Vulnerability (CVE-2019-1181)

Gen.Exploiter.CVE_2019_1181/2

Excluding a protection means that files will not be monitored by Anti-Exploit.

  • Process and protection

    • C:\Program Files\MyTrustedDirectory\excludeMe.exe

    • Gen.Exploiter.ROP

  • Protection

    • Gen.Exploiter.ROP