<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you for your replies in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962944#M1780</link>
    <description>&lt;P&gt;Thank you for your replies and suggestions. &amp;nbsp;I wont be able to test any of this until Monday, but will get back to you then with an update.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2016 06:43:51 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2016-09-16T06:43:51Z</dc:date>
    <item>
      <title>Issues excluding a custom application from being scanned</title>
      <link>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962941#M1719</link>
      <description>&lt;P&gt;As the title &amp;nbsp;says, I am having problems excluding a custom application from being scanned. &amp;nbsp;I have added the file path with a wild card (*) as well as the .exe file location (just for testing) without success. &amp;nbsp;Once the application is installed it is scanned and some components deleted. &amp;nbsp;the install location is under "Users" and not Program Files. &amp;nbsp;I am starting to think that it is installing some files elsewhere as well.&lt;/P&gt;
&lt;P&gt;C:\Users\*\Mapis Data Input Tool&lt;/P&gt;
&lt;P&gt;Any ideas what might be going wrong? is my syntax incorrect for the exclusion? or perhaps I should be placing this under Path instead of Wildcard?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962941#M1719</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-02-21T05:01:54Z</dc:date>
    </item>
    <item>
      <title>The exclusion looks like a</title>
      <link>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962942#M1749</link>
      <description>&lt;P&gt;The exclusion looks like a valid wildcard. Be sure that your endpoint policy has actually updated and has the exclusion you have added to your list (you can check this under the settings in the UI).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you have any detection events you will want to compare those against you exclusion to be sure that multiple paths aren't in use.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 14:07:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962942#M1749</guid>
      <dc:creator>aledipas</dc:creator>
      <dc:date>2016-09-15T14:07:42Z</dc:date>
    </item>
    <item>
      <title>Hello Marius,</title>
      <link>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962943#M1766</link>
      <description>&lt;P&gt;Hello Marius,&lt;/P&gt;
&lt;P&gt;For application whitelisting, it will be better if you define under Outbreak Control &amp;gt;&amp;nbsp;Application Control - Whitelisting. Upload the application file into the Cloud Console or you may add the SHA-256 value manually for file exclusion.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 03:36:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962943#M1766</guid>
      <dc:creator>george.seah</dc:creator>
      <dc:date>2016-09-16T03:36:12Z</dc:date>
    </item>
    <item>
      <title>Thank you for your replies</title>
      <link>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962944#M1780</link>
      <description>&lt;P&gt;Thank you for your replies and suggestions. &amp;nbsp;I wont be able to test any of this until Monday, but will get back to you then with an update.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 06:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962944#M1780</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2016-09-16T06:43:51Z</dc:date>
    </item>
    <item>
      <title>I tried adding the SHA value</title>
      <link>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962945#M1789</link>
      <description>&lt;P&gt;I tried adding the SHA value under application control whitelisting but did not work. &amp;nbsp;what happens is that I install the program via a .exe file and then once installed and I try to run it, it gets blocked.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I hope to get some more time tomorrow to test possible solutions.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 14:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962945#M1789</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2016-09-28T14:24:11Z</dc:date>
    </item>
    <item>
      <title>Marius,</title>
      <link>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962946#M1804</link>
      <description>&lt;P&gt;Marius,&lt;/P&gt;
&lt;P&gt;Were you able to perform additional testing and check the detection events as Alex suggested? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2016 13:01:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962946#M1804</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2016-10-06T13:01:46Z</dc:date>
    </item>
    <item>
      <title>I have not yet had time to</title>
      <link>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962947#M1813</link>
      <description>&lt;P&gt;I have not yet had time to check the detection events. &amp;nbsp;I have however added the two sha values that were shown as blocked to whitelist. without any success.&lt;/P&gt;
&lt;P&gt;I have been swamped with other cases which have taken priority over this so I will be coming back to this once the load lightens.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2016 13:05:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/issues-excluding-a-custom-application-from-being-scanned/m-p/2962947#M1813</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2016-10-06T13:05:13Z</dc:date>
    </item>
  </channel>
</rss>

