This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos default exclusions, List?

Hello!

 

Is there a list of the default Sophos Endpoint AV exclusions (especially for Windows)?

 

I'm currently installing Sophos Endpoint on serveral clients (via Sophos Central) and I'm checking, which additional exclusions I will need.

I'm aware of the "Recommended vendor exclusions for use with Sophos products (Windows)"  (https://community.sophos.com/kb/en-us/35970), but certainly Sophos does already have some of these already set. Especially the basic windows exclusions.

 

Where can I find such a list?

 

Regards

 Sven



This thread was automatically locked due to age.
Parents Reply Children
  • I was not asking how to define exclusions!

     

    You said "Other than vendor exclusions list, we do not have any specific list for default exclusions."

    But what does this mean?

    I want to see a list, which shows all the default exclusions of Sophos AV.

    Does Sophos use all the entries in the vendor exclusion list per default? I do not understand this.

     

    As an example Microsoft recommends to exclude the following files:

       NTUser.pol,  Registry.pol,  Registry.tmp

    which belong to the Group-Policy mechanism of Windows.

    Most likely Sophos AV does already exclude these files per default. Otherwise Sophos AV could break the whole Windows System and/or Windows Security mechanisms.

     

    Where can I find such a list?

     

    Regards

     Sven

  • Hello Sven,

    there are, AFAIK, no predefined exclusions for desktop computers. Automatic exclusions (if the setting is enabled) are only applied to certain products.

    You are perhaps referring to articles like Virus scanning recommendations for Enterprise computers that are running currently supported versions of Windows. Before I get to the mentioned examples I read the following (emphases mine): may help an administrator determine the cause of potential instability. Then temporarily apply [...] to evaluate. And evaluate the risks, [...] take any appropriate additional steps to help protect [...] We do not recommend this workaround [...] Use this workaround at your own risk [...] Your system will be safer if you do not exclude any files or folders from scans.
    This is clearly not a call for proactive automatic exclusions, IMO the contrary.

    Christian