Threat Emulation -> Anti-Exploit Exclusions
Threat Emulation -> Anti-Exploit Exclusions
You can exclude these elements from the Anti-Exploit protection:
-
Protection Name - Predefined malware signature
-
Process - To exclude an executable
Currently there are five different Anti-Exploit protections available. Following is a list of the protections per-name.
Syntax for exclusions:
|
Protection |
Protection Rule Name |
|---|---|
|
Import-Export Address Table Parsing |
Gen.Exploiter.IET |
|
Return Oriented Programming |
Gen.Exploiter.ROP |
|
VB Script God Mode |
Gen.Exploiter.VBS |
|
Stack Pivoting |
Gen.Exploiter.SP |
|
RDP Vulnerability (CVE-2019-0708) |
Gen.Exploiter.CVE_2019_0708 |
|
RCE Vulnerability (CVE-2019-1181) |
Gen.Exploiter.CVE_2019_1181/2 |
Excluding a protection means that files will not be monitored by Anti-Exploit.
-
Process and protection
-
C:\Program Files\MyTrustedDirectory\excludeMe.exe -
Gen.Exploiter.ROP
-
-
Protection
-
Gen.Exploiter.ROP
-