<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Path Exclusion Also Exclude Processes Within It? in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/does-path-exclusion-also-exclude-processes-within-it/m-p/4155358#M5679</link>
    <description>&lt;P&gt;AndyIT,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are 2 different types of exclusions, you would need PATH exclusions to exclude PATHs, Process Exclusions to exclude processes and child process exclusion is an option for Process Exclusions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 22 Sep 2020 15:38:37 GMT</pubDate>
    <dc:creator>majacob2</dc:creator>
    <dc:date>2020-09-22T15:38:37Z</dc:date>
    <item>
      <title>Does Path Exclusion Also Exclude Processes Within It?</title>
      <link>https://community.cisco.com/t5/endpoint-security/does-path-exclusion-also-exclude-processes-within-it/m-p/4155276#M5678</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created some path exclusions on my AMP console but my question is this, within a path exclusion will this also exclude any processes from being scanned which launch from within said path?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Path Exclusion&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files (x86)\Visual Studio 14.0\&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a few folders deeper within that path there is an .exe will that be excluded from the scans and if so will any child process it calls up be excluded also?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 13:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/does-path-exclusion-also-exclude-processes-within-it/m-p/4155276#M5678</guid>
      <dc:creator>AndyIT</dc:creator>
      <dc:date>2020-09-22T13:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: Does Path Exclusion Also Exclude Processes Within It?</title>
      <link>https://community.cisco.com/t5/endpoint-security/does-path-exclusion-also-exclude-processes-within-it/m-p/4155358#M5679</link>
      <description>&lt;P&gt;AndyIT,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are 2 different types of exclusions, you would need PATH exclusions to exclude PATHs, Process Exclusions to exclude processes and child process exclusion is an option for Process Exclusions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 15:38:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/does-path-exclusion-also-exclude-processes-within-it/m-p/4155358#M5679</guid>
      <dc:creator>majacob2</dc:creator>
      <dc:date>2020-09-22T15:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Does Path Exclusion Also Exclude Processes Within It?</title>
      <link>https://community.cisco.com/t5/endpoint-security/does-path-exclusion-also-exclude-processes-within-it/m-p/4155437#M5680</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1103332"&gt;@AndyIT&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;yes, a path exclusion will stop the connector to monitor (generating data for the backend engines) and scanning anything inside the configured path exclusion. From a security and visibility perspective, having as less as possible exclusions makes sense.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Development environments, i assume this is one, it is most time necessary to exclude developer tools. &lt;BR /&gt;From a best practice view:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Configure as less as possible exclusions.&lt;/LI&gt;
&lt;LI&gt;Generate an own group, policy and exclusion list for Developer endpoints.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;There are two tools available to figure out necessary exclusions on the endpoint:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;AMP tuning tool which processes diagnostic packages:&amp;nbsp;&lt;A href="https://github.com/CiscoSecurity/amp-05-windows-tune" target="_blank"&gt;https://github.com/CiscoSecurity/amp-05-windows-tune&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;AMP Health Checker which gives you a live view into the connector:&amp;nbsp;&lt;A href="https://github.com/CiscoSecurity/amp-05-health-checker-windows" target="_blank"&gt;https://github.com/CiscoSecurity/amp-05-health-checker-windows&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 17:34:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/does-path-exclusion-also-exclude-processes-within-it/m-p/4155437#M5680</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2020-09-22T17:34:25Z</dc:date>
    </item>
  </channel>
</rss>

