cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4357
Views
0
Helpful
4
Replies

Cisco AMP for Endpoints - Wildcard Exclusions

chivudaniel
Level 1
Level 1

Hello,

 

Can I use the Wildcard exclusion capability of Cisco AMP in order to add an exclusion that can propagate on multiple drives, on Windows.  For example, if I will add the wildcard exclusion " *\Folder1\Folder2\ " will this be apply for drive C, D , E etc? (similar with C:\Folder1\Folder2\  or    D:\Folder1\Folder2\)

 

Thanks,


Daniel

4 Replies 4

Troja007
Cisco Employee
Cisco Employee

Hello,

enclosed an info also from AMP manuals. From my side, it should be work as you mentioned.

 

Wildcard exclusions are the same as path or extension exclusions except that you can use an asterisk character as a wild card. For example, if you wanted to exclude your virtual machines on a Mac from being scanned you might enter this path exclusion:

/Users/johndoe/Documents/Virtual Machines/

However, this exclusion will only work for one user, so instead replace the username in the path with an asterisk and create a wild card exclusion instead to exclude this directory for all users:

/Users/*/Documents/Virtual Machines/ 

 

 

Cheers

Hello to all of community,
about this exclusion, with wildcard, if I use AnyDrive option, How do I have to write the exclusion?
In the manual I see use of ^[A-Za-z]\foldername but after applied the rule, I see in the field: anydrive:\^[A-Za-z]\foldername.

Is it correct?
from Manual:
Write an exclusion for paths that exists in separate drives.
Example: C:\testpath and D:\testpath will be:
^[A-Za-z]\testpath
The system automatically generates the ^[A-Za-z] when "Apply to all drive letters" is check boxed after wildcard is selected from the Exclusion Type dropdown.

Now which is the correct syntax to write the exclusion is this case?

only foldername like folderA\folderB\ or ^[A-Za-z]\folderA\folderB\

thanks and regards,

Alex.

The system will add ^[A-Za-z]:\ for you.  Consider you have a folder at C:\test and D:\test on various machines and want to exclude both. You would just put test into the exclusion field.  It will look like this in the console.
screenshot.png

Thanks,

Matt

 

Hi, 

 

thanks for your information...as I think, it is sufficient to write only name folder.

The optio anydrive will use all drive and :\ befor name folder.

 

thanks.

 

Have a nice day, 

 

Alex.