FortiDLP
FortiDLP is a cloud-native endpoint DLP and Insider Risk Solution which is aimed at monitoring and Preventing Data Theft on the endpoint, across Windows, macOS and Linux.
Anthony_E
Community Manager
Community Manager
Article Id 353773
Description This article discusses Directories, Files, and Processes to Exclude from Virus Scanning.
Scope FortiDLP.
Solution

The Reveal Agent has been designed to be as interoperable as possible and only makes use of standard operating system APIs to function, but it does require unrestricted access to its files and directories for best performance. 

 

Processes:

The Reveal Agent consists of many libraries and executables, as well as optional browser and mail client plugins.

Additionally, several folders are used for log files, configuration settings, and temporary files. Next recommends all antivirus software is configured to exclude the following processes and folder locations from any threat protection or virus scanning:

 

Windows:

 

C:\Program Files\Jazz Networks\Agent\service\winsuper.exe
C:\Program Files\Jazz Networks\Agent\agent.exe
C:\Program Files\Jazz Networks\Agent\jazzbrowsermessenger.exe

C:\Program Files\Jazz Networks\Agent\outlookproxy.exe
C:\Program Files\Jazz Networks\Agent\jazzbrowsermessenger.bat
C:\Program Files\Jazz Networks\Agent\jazzdesktop.exe
C:\Program Files\Jazz Networks\Agent\jazzdialog.exe
C:\Program Files\Jazz Networks\Agent\jazzisolate.exe
C:\Program Files\Jazz Networks\Agent\jazzlocker.exe
C:\Program Files\Jazz Networks\Agent\jazzmfa.exe
C:\Program Files\Jazz Networks\Agent\uninstall.exe

C:\Program Files\Jazz Networks\Agent\toaster.exe
C:\Program Files\Jazz Networks\Agent\withdll.exe
C:\Program Files\Jazz Networks\Agent\contentng.exe

C:\Program Files\Jazz Networks\Agent\spool_shim64.dll

 

macOS:

 

/Library/Application Support/Ava/Reveal/agent/agent
/Applications/Reveal Agent.app/Contents/XPCServices/sysmon.xpc/Contents/MacOS/sysmon
/Applications/Reveal Agent.app/Contents/Library/LoginItems/Reveal Agent Helper.app/Contents/MacOS/Reveal Agent Helper
/Applications/Reveal Agent.app/Contents/MacOS/Reveal Agent

/Applications/FortiDLP.app/Contents/XPCServices/sysmon.xpc/Contents/MacOS/sysmon
/Applications/FortiDLP.app/Contents/Library/LoginItems/FortiDLP Helper.app/Contents/MacOS/FortiDLP Helper
/Applications/FortiDLP.app/Contents/MacOS/FortiDLP
/Library/Application Support/Ava/Reveal/JazzBrowserNative.app/Contents/MacOS/JazzBrowserNative
/Library/Application Support/Ava/Reveal/LockHelper.app/Contents/MacOS/LockHelper
/Library/Application Support/Ava/Reveal/jazzoutlook.app/Contents/MacOS/jazzoutlook
/Library/SystemExtensions/*/uk.ava.reveal.agent.eps.systemextension/Contents/MacOS/uk.ava.reveal.agent.eps
/Library/SystemExtensions/*/uk.ava.reveal.agent.net.systemextension/Contents/MacOS/uk.ava.reveal.agent.net
/Library/Application Support/Ava/Reveal/contentng/contentng

 

Linux:

 

/usr/local/jazz/bin/jazz-agent

/usr/local/jazz/bin/contentng
/usr/sbin/jazz-agent

/usr/sbin/contentng
/var/run/jazzplugin

 

Folders:

If the antivirus software does not support the exclusion of all file access monitoring for specific processes or is highlighting/deleting any Reveal files as malicious, it is recommended to exclude the contents of the following folders from any monitoring.

 

Windows:

 

C:\Program Files\Jazz Networks
C:\ProgramData\Jazz Networks
C:\Windows\Temp\jazz
%TEMP%\jazz

\\.\pipe\jazzplugin

\\.\pipe\agent-*

 

MacOS:

 

/Library/Application Support/Ava/**

/Applications/Reveal Agent.app/**

/Applications/FortiDLP.app/**

/etc/jazz/**

/var/jazz/**

/var/run/jazz-agent.sock

/var/folders/ava/**

/private/etc/jazz/**

/private/var/jazz/**

/private/var/run/jazz-agent.sock

/private/var/folders/ava/**

 

Linux:

 

/etc/jazz/**

/proc/jazz/**

/usr/local/jazz/**

/usr/share/jazz/**

/usr/src/jazz-*

/var/lib/dkms/jazz/**

/var/jazz/**

/var/run/jazz-agent.sock

/var/run/jazz-agent.pid