<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Process Exclusion vs Path Exclusion — What is the correct choice in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5349502#M8960</link>
    <description>&lt;P&gt;First of all what would be helpful to understand here is what type of event your see in the console. Meaning would be nice to see picture of the event expanded with all the details to determine which engine is the one responsible for the detection.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Nov 2025 13:24:18 GMT</pubDate>
    <dc:creator>Roman Valenta</dc:creator>
    <dc:date>2025-11-24T13:24:18Z</dc:date>
    <item>
      <title>Process Exclusion vs Path Exclusion — What is the correct choice</title>
      <link>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5348378#M8957</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I’m dealing with a recurring false-positive event related to one of our internal service executables, and I’d like to clarify which exclusion type is considered best practice according to Cisco Secure Endpoint’s engine behavior.&lt;/P&gt;&lt;P&gt;We have an internal agent called &lt;STRONG&gt;AgentWorker.exe&lt;/STRONG&gt;, located here:&lt;/P&gt;&lt;PRE&gt;C:\Program Files\CompanyAgent\Service\AgentWorker.exe&lt;/PRE&gt;&lt;P&gt;This executable periodically launches PowerShell in non-interactive mode with encoded command parameters.&lt;BR /&gt;This behavior is fully legitimate and part of the expected workflow.&lt;/P&gt;&lt;P&gt;In Secure Endpoint, the event shows details similar to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Parent Process:&lt;/STRONG&gt; AgentWorker.exe&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Child Process:&lt;/STRONG&gt; powershell.exe&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Event Type:&lt;/STRONG&gt; Process start / file scan&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;No threat name is involved&lt;/STRONG&gt; (so it’s not a malware-based detection)&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;Process Start&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;powershell.exe&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;by&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SYSTEM&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Arguments = C:\Windows\System32\MsiExec.exe -Embedding 19999999999874 E Global\MSI9999&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We do &lt;EM&gt;not&lt;/EM&gt; want to exclude PowerShell globally.&lt;BR /&gt;We also do &lt;EM&gt;not&lt;/EM&gt; want to remove AgentWorker.exe entirely from MAP, BP, SPP, or File Scan engines.&lt;BR /&gt;The goal is only to prevent this single executable from being incorrectly scanned or blocked.&lt;/P&gt;&lt;P&gt;So I’d like to clarify the following:&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;&lt;STRONG&gt;1. In this scenario, what is the most appropriate exclusion type according to Cisco’s recommendations?&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;Should I use a:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;a) Path Exclusion&lt;/STRONG&gt; for:&lt;/P&gt;&lt;PRE&gt;C:\Program Files\CompanyAgent\Service\AgentWorker.exe&lt;/PRE&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;b) Process Exclusion&lt;/STRONG&gt;, even though this would bypass multiple engines for the entire process?&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;&lt;STRONG&gt;2. Have there been any recent changes to the behavior of Path or Process exclusions?&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;I have reviewed Document ID &lt;STRONG&gt;215418 – Configure and Manage Exclusions&lt;/STRONG&gt;, but it’s still unclear how to handle this type of “file start + PowerShell child process” scenario in the most secure and correct way.&lt;/P&gt;&lt;P&gt;Any guidance from Cisco engineers or other users with similar setups would be highly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 12:55:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5348378#M8957</guid>
      <dc:creator>chickenriceandbeans</dc:creator>
      <dc:date>2025-11-19T12:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Process Exclusion vs Path Exclusion — What is the correct choice</title>
      <link>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5348411#M8958</link>
      <description>What kind of detection is it?  For some of the engines, you have to open a TAC case.  Exploit prevention and I think Behavioral detections.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 19 Nov 2025 14:37:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5348411#M8958</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2025-11-19T14:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Process Exclusion vs Path Exclusion — What is the correct choice</title>
      <link>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5349435#M8959</link>
      <description>&lt;P&gt;Hi, what I’m trying to say is this:&lt;BR /&gt;My goal is to whitelist a specific PowerShell prompt. When that prompt is triggered, I don’t want it to be seen as risky. For me it’s not a problem, so I want it to be allowed.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Nov 2025 08:15:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5349435#M8959</guid>
      <dc:creator>chickenriceandbeans</dc:creator>
      <dc:date>2025-11-24T08:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Process Exclusion vs Path Exclusion — What is the correct choice</title>
      <link>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5349502#M8960</link>
      <description>&lt;P&gt;First of all what would be helpful to understand here is what type of event your see in the console. Meaning would be nice to see picture of the event expanded with all the details to determine which engine is the one responsible for the detection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Nov 2025 13:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5349502#M8960</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2025-11-24T13:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Process Exclusion vs Path Exclusion — What is the correct choice</title>
      <link>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5349724#M8961</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chickenriceandbeans_0-1764055177881.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/255761iCA3BBB3510FD9D20/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chickenriceandbeans_0-1764055177881.png" alt="chickenriceandbeans_0-1764055177881.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chickenriceandbeans_1-1764055358182.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/255762iFAC369DA020B7B9E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chickenriceandbeans_1-1764055358182.png" alt="chickenriceandbeans_1-1764055358182.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 07:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5349724#M8961</guid>
      <dc:creator>chickenriceandbeans</dc:creator>
      <dc:date>2025-11-25T07:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Process Exclusion vs Path Exclusion — What is the correct choice</title>
      <link>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5349864#M8962</link>
      <description>&lt;P&gt;Unfortunately I cant tell form that picture what engine is triggering this event. I would suggest to look in Device Trajectory and also you can some time tell from the first line&amp;nbsp; of the event&amp;nbsp; not expanded. By any chance did yours is triggered by Exploit Prevention like this example bellow ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_4060.png" style="width: 826px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/255782i6634FD93BB216EF5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_4060.png" alt="Screenshot_4060.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 15:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/process-exclusion-vs-path-exclusion-what-is-the-correct-choice/m-p/5349864#M8962</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2025-11-25T15:32:52Z</dc:date>
    </item>
  </channel>
</rss>

