Created on 10-29-2024 06:56 AM Edited on 11-22-2024 06:49 AM
| Description | This article discusses Directories, Files, and Processes to Exclude from Virus Scanning. |
| Scope | FortiDLP. |
| Solution |
The Reveal Agent has been designed to be as interoperable as possible and only makes use of standard operating system APIs to function, but it does require unrestricted access to its files and directories for best performance.
Processes: The Reveal Agent consists of many libraries and executables, as well as optional browser and mail client plugins. Additionally, several folders are used for log files, configuration settings, and temporary files. Next recommends all antivirus software is configured to exclude the following processes and folder locations from any threat protection or virus scanning:
Windows:
C:\Program Files\Jazz Networks\Agent\service\winsuper.exe C:\Program Files\Jazz Networks\Agent\outlookproxy.exe C:\Program Files\Jazz Networks\Agent\toaster.exe C:\Program Files\Jazz Networks\Agent\spool_shim64.dll
macOS:
/Library/Application Support/Ava/Reveal/agent/agent /Applications/FortiDLP.app/Contents/XPCServices/sysmon.xpc/Contents/MacOS/sysmon
Linux:
/usr/local/jazz/bin/jazz-agent /usr/local/jazz/bin/contentng /usr/sbin/contentng
Folders: If the antivirus software does not support the exclusion of all file access monitoring for specific processes or is highlighting/deleting any Reveal files as malicious, it is recommended to exclude the contents of the following folders from any monitoring.
Windows:
C:\Program Files\Jazz Networks \\.\pipe\jazzplugin \\.\pipe\agent-*
MacOS:
/Library/Application Support/Ava/** /Applications/Reveal Agent.app/** /Applications/FortiDLP.app/** /etc/jazz/** /var/jazz/** /var/run/jazz-agent.sock /var/folders/ava/** /private/etc/jazz/** /private/var/jazz/** /private/var/run/jazz-agent.sock /private/var/folders/ava/**
Linux:
/etc/jazz/** /proc/jazz/** /usr/local/jazz/** /usr/share/jazz/** /usr/src/jazz-* /var/lib/dkms/jazz/** /var/jazz/** /var/run/jazz-agent.sock /var/run/jazz-agent.pid |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.