Skip to main content

Category filter

Configuring and Managing Exclusions in Hexnode XDR

TL;DR

Exclusions in Hexnode XDR prevent trusted files, folders, hashes, publishers, and file extensions from triggering false-positive threat alerts. You can configure these exclusions within policies, from flagged incidents, or globally across all endpoints via the Global Default Policy. Once created, all active exclusions are centrally managed in the Exclusions Repository under the Incidents tab, allowing you to easily track the specific policies and devices linked to each rule.

Hexnode XDR continuously monitors system calls across your endpoints to detect suspicious behavior. While this vigilance keeps your environment secure, it can occasionally lead to performance overhead or flag a trusted item, such as an internal application, as a threat.

Exclusions in Hexnode XDR let you specify exactly what the XDR agent should ignore. When you exclude a trusted file, folder, publisher, hash, or file extension, real-time monitoring is disabled for that item. Routine activity involving it (opening, editing, moving) no longer triggers incident alerts.

This guide covers how to create exclusions and how to manage them in Hexnode XDR.

Exclusion types at a glance

Exclusion type Supported Platforms Use it when
File / Folder Windows, macOS An internal or custom-built application at a known path keeps getting flagged.
File Extension Windows only A trusted vendor’s software generates frequent false positives. Excluding the publisher suppresses alerts for all present and future applications signed by them.
Hash (SHA 1 / SHA 256) Windows, macOS You need to identify one specific binary, wherever it’s copied or however it’s renamed.
Publisher Windows, macOS A file type is used routinely and is low-risk across your environment.

Create Exclusions

You can create an exclusion in two ways:

  1. From the Policies tab: Add exclusions as part of a policy’s configuration.
  2. From the Incidents tab: Add an exclusion directly from a flagged incident.

To view and manage all exclusions afterward, use the Exclusions Repository.

Method 1: Creating exclusions from the Policies tab

  1. Log in to Hexnode XDR.
  2. Go to the Policies tab and click New Policy.

Step 1: Configuration

  1. Select the OS platform — Windows, or macOS.
  2. Click on Exclusions. The Exclusions section expands into four exclusion types:
    • File/Folder
    • Publisher
    • Hash
    • File Extension (Windows only)
  3. Select an exclusion type and click on Configure, then follow the instructions for that type below.
  4. Click Next when you’ve finished configuring your exclusions.

Follow the steps below to configure each exclusion type.

File/Folder

Specify the file or folder paths you want to exclude from your incident stream.

  • From the dropdown, choose File or Folder.
  • In the text field, enter the full path of the file or folder. For example, C:\Program Files\Acme\acme.exe on Windows or /Applications/Acme.app on macOS.
  • For a folder, enable the Include sub-folder option if the exclusion should also cover every sub-folder inside the specified folder.
  • Click Add to save the entry to the table.

Screenshot of Hexnode XDR portal displaying the File/Folder exclusion type in Policies.

Publisher

Exclude trusted software from being flagged as threats by specifying its publisher and code-signing identity.

  • Enter the Publisher Name.
  • (Optional, recommended) Enter the Certificate Thumbprint (Windows) or Team ID (macOS). Adding one verifies the publisher’s identity and makes the exclusion more precise.
  • Click Add to save the entry to the table.

Screenshot of Hexnode XDR portal displaying the Publisher exclusion type in Policies.

Hash

Exclude a specific binary by its hash value.

  • Choose SHA 1 or SHA 256 from the dropdown.
  • Enter the hash value in the text field.
  • Click Add to save the entry to the table.

Screenshot of Hexnode XDR portal displaying the Hash exclusion type in Policies.

File Extension (Windows only)

Exclude all files with a particular extension (for example, .xml or .tmp) so they are no longer flagged as threats. Once an extension is excluded, files of that type no longer trigger incident notifications.

  • Enter the file extension in the text field.
  • Click Add to save the entry to the table.

Screenshot of Hexnode XDR portal displaying the File extension exclusion type in Policies.

Step 2: Targets

  1. On the Targets page, choose where the policy should apply:
    • Endpoints: Click Add Endpoints, select endpoints from the list, then click Add.
    • Endpoint groups: Click Add Endpoint Group, select groups from the list, then click Add.
  2. Click Next to reach the Review page.

Screenshot of Hexnode XDR portal displaying the Targets page in Policies.

Step 3: Review

The Review page displays a preview of the policies you’ve configured in the previous steps.

  1. In the policy preview, under Exclusions, click Edit to go back to the configuration page and make changes.

    Screenshot of Hexnode XDR portal displaying the Review page in Policies.

  1. Click Save, then choose one of the following:
    • Save Draft: saves the policy so you can publish it later.
    • Publish: applies the policy to the selected targets immediately.

Once the policy is published, the exclusions you configured apply to the selected endpoints and endpoint groups. On those endpoints, the excluded items are no longer flagged as threats, and activity involving them won’t trigger incident notifications.

Method 2: Creating an exclusion from the Incidents tab

Use this method when you want to exclude a specific file, publisher, or hash directly from a flagged incident.

  1. Open the Incidents tab and click on the specific incident.
  2. Click on Action, then select Add to Exclusion Policy.
  3. Screenshot of Hexnode XDR portal displaying the Add to Exclusion Policy action in a specific incident.

  1. In the window that appears, select the exclusion types.
  2. Note:


    The available exclusion types for the incident depend on the data captured from the incident. Depending on the incident, you may see the following extension types:

    • File/Folder
    • Publisher
    • Hash (SHA-256 / SHA-1)
    • File Extension

    Screenshot of Hexnode XDR portal displaying the Exclusion types in a specific incident.

  3. As you select each type, it’s added to the right side of the window with its fields already filled in from the incident’s data. These values are read-only and can’t be edited.

Screenshot of Hexnode XDR portal displaying the Exclusion types selected in a specific incident.

  1. Click Next.
  2. Select the policy you want to add the exclusion to, and then click Save.

Screenshot of Hexnode XDR portal displaying the Exclusion policy association page.

Once saved, the selected items are added as exclusions to that policy. On every endpoint the policy applies to, these items are no longer flagged as threats, and activity involving them won’t trigger incident notifications.

Managing exclusions: The Exclusions Repository

Screenshot of Hexnode XDR portal displaying the Exclusions sub-tab in Incidents.

The Exclusions subtab, located under the Incidents tab, provides a centralized, tabular view of all active exclusions created across the Hexnode XDR portal.

You can use the Group by option to organize the table by Exclusion Type, or use the Filter menu to narrow results by Exclusion Type (File, Folder, Publisher, File Extension, Hash based – SHA 1 or Hash based – SHA 256) or Platform (Windows, macOS).

Table columns:

Column Details
Exclusion Value The excluded file/folder path, publisher, hash value, or file extension.
Platform Windows and/or macOS
Exclusion Type File/Folder, Publisher, Hash, or File Extension
Linked Policies Policy names where this exclusion is applied
Number of devices associated Total devices this exclusion currently applies to
Note:

  • Linked policies:
    1. Each policy name in the Linked Policies column is a hyperlink to that policy’s view page.
    2. If an exclusion is linked to multiple policies, the column shows the first policy’s name plus a +N icon, where ‘N’ is additional policies where the exclusion is configured.
    3. Click the badge to open a scrollable list of all linked policies. You can search the list and open any policy from it.
  • Number of Devices Associated: The device count value in the Number of Devices Associated column is a clickable link. Click it to open a scrollable list of every device the exclusion applies to.

Frequently Asked Questions

What if a trusted item must be excluded across all endpoints in the XDR portal?

To exclude that item across all endpoints in the XDR portal, you can add it to the Global Default Policy. An exclusion in the Global Default Policy covers every endpoint in the portal.

  1. Go to the Policies tab and select Default Policy.
  2. Click Manage and select Edit.
  3. In the Exclusions section, click Edit and add the exclusions.
Which exclusion types are available on macOS?

On macOS you can exclude files and folders, publishers, and hashes (SHA-1 or SHA-256). File extension exclusions are available on Windows only.

How can I see where an exclusion is applied?

Open the Exclusions subtab under the Incidents tab. In the Linked Policies column, click a policy name to open that policy, or click the +N badge to see all linked policies. In the Number of Devices Associated column, click the count to see every device the exclusion applies to.

Policies