Policy exclusions for Windows Defender processes
search cancel

Policy exclusions for Windows Defender processes

book

Article ID: 286373

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard Carbon Black Cloud Enterprise EDR

Issue/Introduction

Creating policy exclusions needed to prevent scan of Windows Defender processes

Environment

  • Carbon Black Cloud Console: All Versions
    • Endpoint Standard Sensor: All Versions
    • Enterprise EDR: All Versions
  • Microsoft Windows Defender

Resolution

Add an Event Reporting & Sensor Operations Exclusion to the Sensor tab in relevant policies:

Exclusion Type: All reporting and sensor operations
Process Type: Process
Process Attribute: Path
Paths: 
c:\programdata\microsoft\windows defender\platform\*\msmpeng.exe
c:\program files\windows defender advanced threat protection\mssense.exe
Inheritance: (OPTIONAL)

Additional Information

The above is an example of the primary Microsoft Defender processes; however, the rule might need to be modified further to adjust for new binaries and/or environmental variables.