Smart Exclusions
With Smart Exclusions, administrators can:
Set exclusions to all capabilities and operating systems at once.
Use standard syntax across all exclusion types.
Use a wider range of wildcard characters for nuanced and customized exclusion patterns.
Easily enable or disable exclusions with a simple toggle button, without the need to delete exclusions temporarily.
Smart Exclusions are supported only with Endpoint Security Client version E87.52 and higher for Windows, and E87.50 and higher for macOS.
Adding Exclusions to a Specific Rule
-
Go to Policy > Threat Prevention > Policy Capabilities.
-
Select the rule for which the exclusion is to be created.
-
In the Capabilities & Exclusions pane, click Exclusions Center.
-
Click Go to Smart Exclusions.
-
Click Create New Exclusion.
-
Select the exclusion type:
Single-method exclusion - Add an exclusion for only one exclusion type.
Multi-method exclusion - Add exclusions for multiple types of exclusions.
-
Enter a name for the exclusion and make sure the status is Enabled.
-
Apply the exclusion to all supported capabilities, or select Select specific and choose the required capabilities from the Capabilities list.
-
(Optional) To enable Chained Exclusions, in the Chained Exclusion are available for section, turn on Inherit exclusion to child processes.
This automatically excludes all the child processes of the excluded process.
Note:With the Endpoint Security Client version E88 and higher, Chained Exclusions support only the Forensics Monitoring capability.
-
Enter the exclusion details and click OK.
Note:For supported syntax and capabilities for exclusion types, see sk181679.
-
Click Save & Install.
A Single-method exclusion can be changed to a Multi-method exclusion. See Managing Exclusions.
Adding Global Exclusions
-
Go to Policy > Threat Prevention > Global Exclusions.
-
Click Go to Smart Exclusions.
Click Create New Exclusion.
-
Select the exclusion type:
Single-method exclusion - Add an exclusion for only one exclusion type.
Multi-method exclusion - Add exclusions for multiple types of exclusions.
-
Enter the required exclusion details.
-
Click Save.
The exclusions are automatically enforced on the client without installing the policy.
A Single-method exclusion can be changed to a Multi-method exclusion. See Managing Exclusions.
Migrating Legacy Exclusions
Best Practice - Check Point recommends following these steps before migrating to Smart Exclusions:
-
Go to Policy > Threat Prevention > Policy Capabilities.
-
Pick a rule to test the migration and clone the rule.
-
Place the newly created rule at the top.
-
Under Applied To, select a test group.
-
Click Exclusion Center for the newly created rule and export the legacy exclusions for backup purposes.
-
For the newly created rule, migrate to Smart Exclusions.
-
Click Save and Install.
-
Go to Logs and filter the logs for the computer in the test group. Verify there are no false positives and all the detections are excluded correctly.
-
If there are issues, contact Check Point Support.
-
Perform the steps for each rule one at a time.
-
Repeat the process for Global Exclusions.
To migrate legacy exclusions for a rule
-
Go to Policy > Threat Prevention > Policy Capabilities.
-
Select the rule.
-
In the Capabilities & Exclusions pane, click Exclusions Center.
-
To migrate legacy global exclusions, go to Policy > Threat Prevention > Global Exclusions.
-
Click Go to Smart Exclusions.
To migrate all legacy exclusions
-
Click Migrate from Legacy Exclusions (available only if there are no exclusions), or click All exclusions from legacy. The Import All Legacy Exclusions window appears.
-
(Recommended) To remove all the legacy exclusions after migrating to Smart Exclusions, select Remove all the imported exclusions from legacy.
-
Click Import.
To migrate specific exclusions
-
Click Select exclusions from legacy. The Transfer from Legacy - Select Exclusions window appears.
-
Select the exclusions.
-
Click OK. The exclusions are added to Smart Exclusions.
-
For a specific rule, click OK and Save & Install.
-
For global exclusions, click Save. The exclusions are automatically enforced on the client without installing the policy.
Importing and Exporting Exclusions
Exclusions can be imported or exported in the JSON format, either for a specific rule or as global exclusions.
-
To import or export exclusions for a rule, go to Policy > Threat Prevention > Policy Capabilities, select the rule, and in the Capabilities & Exclusions pane, click Exclusions Center.
-
To import or export global exclusions, go to Policy > Threat Prevention > Global Exclusions.
-
Click Go To Smart Exclusions.
-
To import exclusions, click Import Files, browse, and select the import file in the JSON format.
-
For a specific rule, click OK and Save & Install.
-
For global exclusions, click Save.
The exclusions are automatically enforced on the client without installing the policy.
-
To export exclusions, click the export icon. The file is exported in the JSON format.