Hi all,
Been reading a number of articles on this site around what System exe's you should exclude from Appsense hooks. There seems to be a number articles around EM excludes but nothing really specific around AM.
For clarity i am taking about ExProcessesNames, AsModLdr and DriverHookEx that are configured in Advanced>Custom Settings in the AM console and in the registry for AsModLdr
First question is there an AM specific list or should the list be the same as the List used for EM. Based on the current lists i have in my old configs they look almost identical.
Second question: Is it necessary to include the AM exe's in the AM exclude lists (AmAgent.exe, AmAgentAssist.exe, AMDllInjectionAssist.exe) as it seems a bit strange we need to define AM exe's to be excluded from themselves
The default exclusion list applied when you install the EM agent (10.1 FR2) seems to be quite comprehensive, compared to the default AM excludes which only lists 4 exe's (MicrosoftEdgeCP.exe,fontdrvhost.exe,FlashUtil_ActiveX.exe,FlashPlayerApp.exe) hence why I thought i would ask here.
Cheers