File Exceptions

You can create an exception to allow or block a hash or a file that was analyzed with a specific risk level.

Note:
  • You can create a file exception to allow only if the file is known to the organization and you want to remove it from the dashboard alerts.

  • You can create a file exception to block if you consider the file is malicious or banned by your organization even though it was determined as Low Risk by the ThreatCloud.

  • You can add up to 100 entries to the File Exceptions list.

To add a file exception:

  1. Go to Policy and select a policy profile.
  2. Click File > File Protection > File Exceptions.
  3. Click Add.

    A pop-up window appears.

  4. Do one of these:
    1. To add a file hash exception:
      1. Click Paste Hash.
      2. In the File Hash field, enter the file hash name. For example, SHA256.
    2. To add a file exception:
      1. Click Upload File.
      2. Click Upload to upload the file.
  5. (Optional) In the Comment field, add your comments.
  6. From the Action list, select one of these:
    • Block - To block the file or file hash.

    • Allow - To allow the file or file hash.

  7. To save the policy changes, click Save.
Note:

You can also allow or block a file from the Forensics > Events & Alerts page.

Select any one of these:

  • Allowed List - The risk level of the file changes to No Risk.

  • Blocked List - The risk level of the file changes to High Risk. A blocked file triggers on-device mitigation and user event notification.