How to configure the F-Secure end-point protection client from scanning when Installing 3rd party EDR software? - WithSecure Community
<main>
<article class="userContent">
<h3 data-version="3" data-article="000018299" data-id="issue">Issue:</h3>
<p>When installing a 3rd party EDR client on a computer running an F-Secure endpoint protection software, which are the recommended exclusions to bypass the F-Secure client in context of the EDR solution?<br> </p>
<h3 data-id="resolution">Resolution:</h3>
<p><br>You can exclude any and all files residing the in the directory pointed to by this registry key:<br></p><ul><li>HKEY_LOCAL_MACHINE\SOFTWARE\F-Secure\Ultralight\Settings\product.paths</li></ul>
The value will contain the directory to skip (also include content of sub directories in the exclusion). <br>Note that this approach works with Ultralight based F-Secure products (CS 13 and later, Server Security 14.x and later).<br><br>If a broad exclusion of our product folder is not acceptable, use the following alternative<br><br>As previously, read the product path value from <b>HKEY_LOCAL_MACHINE\SOFTWARE\F-Secure\Ultralight\Settings\product.paths</b><br>Then construct the exclusion using the following logic.<br><br><b><product-path>*\Ultralight\ulcore\*\fsorsp*.exe<br><product-path>*\Ultralight\ulcore\*\fshoster*.exe</b><br><br>(the wildcard "*" represents here 0 or more characters)<br><br>For example, if the product installed in the folder C:\Program Files (x86)\F-Secure\Client Security\<br>the exclusion should match:<br><br><b>C:\Program Files (x86)\F-Secure\Client Security\Ultralight\ulcore\1570191397\fsorsp64.exe<br>C:\Program Files (x86)\F-Secure\Client Security\Ultralight\ulcore\1570191397\fshoster64.exe</b><br><br>Please note that exclusions fshoster*.exe and fsorsp*.exe cover both 32 and 64 bit operating-systems e.g. fsorsp64.exe or fsorsp32.exe both should match the above pattern.
<p>Article no: 000018299</p>
</article>
</main>