Trusted process window
In this window, you can add and configure exclusion scopes for exclusion by process.
Exclusion scope settings for exclusion by process
Setting
|
Description
|
Exclusion scope name
|
Field for entering the exclusion scope name. This name will be displayed in a table in the Exclusions by process window.
The entry field must not be blank.
|
Path to excluded process
|
Full path to the process you want to exclude from scans.
|
Apply to child processes
|
Exclude child processes of the excluded process indicated by the Path to excluded process setting.
This check box is cleared by default.
|
Use this scope
|
The check box enables or disables this exclusion scope.
If this check box is selected, the application excludes this area during scans.
If this check box is cleared, the application includes this area in the scan scope. You can later exclude this scope by selecting the check box.
The check box is selected by default.
|
Path to modified files
|
This group of settings lets you set scan exclusions for files modified by the process.
In the drop-down list of file systems, you can select the type of file system of the directories to be excluded from scans:
- Local, for local directories. If this item is selected, you need to indicate the path to the local directory.
- Mounted – Mounted remote or local directories. If this item is selected, you need to indicate the protocol or name of the file system.
- Shared — The protected server's file system resources accessible via the Samba or NFS protocol.
- All remote mounted – all remote directories mounted on the device using the Samba and NFS protocols.
- All shared — All of the protected server's file system resources accessible via the Samba and NFS protocols.
|
If Mounted or Shared is selected in the drop-down list of file systems, then you can select the remote access protocol in the drop-down list of access protocols:
- NFS: remote directories mounted on a device using the NFS protocol.
- Samba: remote directories mounted on a device using the Samba protocol.
- Custom – resources of the device's file system specified in the field below.
|
If Local is selected in the drop-down list of file systems, then in the input field you can enter a path to a directory that you want add to the exclusion scope. You can use masks to specify the path. The entry field must not be blank.
You can use the * (asterisk) character to create a file or directory name mask.
You can indicate a single * character to represent any set of characters (including an empty set) preceding the / character in the file or directory name. For example, /dir/*/file or /dir/*/*/file .
You can indicate two consecutive * characters to represent any set of characters (including an empty set and the / character) in the file or directory name. For example, /dir/**/file*/ or /dir/file**/ .
The ** mask can be used only once in a directory name. For example, /dir/**/**/file is an incorrect mask.
To exclude the mount point /dir , you need to specifically indicate /dir (no asterisk).
The mask /dir/* excludes all mount points at the level below /dir but not /dir itself. The /dir/** mask excludes all mount points below the level of /dir but not /dir itself.
You can use a single ? character to represent any one character in the file or directory name.
|
Filesystem name
|
The field for entering the name of the file system where the directories that you want to add to the exclusion scope are located.
The field is available if the Mounted type is selected in the drop-down list of file systems and the Custom item is selected in the drop-down list on the right.
|
Masks
|
The list contains name masks of the objects that the application excludes from scan. Masks are only applied to objects in the directory specified in the Path to modified files field.
You can add, edit, or delete masks.
Clicking the Delete button causes Kaspersky Embedded Systems Security to remove the selected name mask of files excluded from a scan.
This button is available if at least one file mask is selected in the list.
Clicking the mask opens the Object mask window. In this window, in the Define object mask field, you can modify the name template for files that Kaspersky Embedded Systems Security excludes from scans.
Clicking the Add button opens the Object mask window. In this window, in the Define object mask field, you can specify the name template for files that Kaspersky Embedded Systems Security excludes from scans.
Examples:
The *.txt mask refers to all text files.
The *_my_file_??.html mask refers to html files starting with any characters, and ending with _my_file_ followed by any two characters (for example, 2020_my_file_09.html).
|
|
Page top
[Topic 248958]