Objective
To provide guidance on configuring Endpoint Protection Platforms (EPP), Next-Gen Antivirus (NGAV), and Endpoint Detection & Response (EDR) exclusions to prevent false positives and interference with Automox Agent installation and policy execution.
Overview
Because the Automox Agent installs software updates, executes remediation scripts, and modifies system configurations, certain security tools may flag Automox behavior as a false positive.
To ensure uninterrupted endpoint management and patching, administrators should configure global trust-listing (exclusions) for Automox within their security platform console.
Recommended Exclusion Strategy
| Exclusion Method | Recommended? | Details |
| Path / Directory-Based Exclusions | Yes (Preferred) | Highly recommended. Path-based rules persist across Automox Agent version updates without requiring ongoing maintenance. |
| Hash-Based Exclusions | No (Fallback) | Not recommended as a primary strategy. Because Automox updates its agent binaries regularly, SHA-256 hashes change with each update, requiring frequent manual policy revisions. |
📌 Directory Exclusions Path Reference: Refer to [Location of Files Required By Automox](Location of Files Required By Automox) for the full list of local agent binaries, installation folders, and working directories required for exclusion.
Vendor Exclusions Setup Resources
Refer to your specific EPP/EDR vendor documentation to configure path-based process and directory exclusions:
-
SentinelOne:
Refer to the SentinelOne Management Console guide on Exclusions & Scope Hierarchy.
- Scope Hierarchy with Exclusions and Blacklists in the SentinelOne Management Console (Video)
- Exclusions in the SentinelOne Management Console (video)
-
CrowdStrike Falcon:
Configure Process Exclusions or Sensor Visibility Exclusions within the Falcon console under Configuration > Prevention Policies.
-
Carbon Black:
Configure Permissions & Exclusions within Carbon Black Cloud console settings.
Carbon Black Product Tour (Video)
-
BlackBerry CylancePROTECT:
Add Automox executable paths to the Memory Protection and Script Control exclusion lists.
-
Microsoft Defender for Endpoint:
Configure process and path exclusions via Microsoft Intune or Microsoft Defender Security Center.