Interoperability with Cisco AMP

Description


To learn how to exclude files and folders please see Capture Client Interoperability Issues with Third Party Applications.





Resolution


Items to exclude:

  • Folder:\Device\HarddiskVolume?\Program Files\Cisco\AMP\ (include subfolders)

Items to exclude Capture Client from Cisco AMP:

  1. Exclude these folders and the update file:

    • C:\Program Files\SentinelOne

    • C:\ProgramData\Sentinel

    • C:\Documents and Settings\All Users\Application Data\Sentinel (ProgramData for 2003 and legacy agents )

    • C:\Windows\Temp\SentinelInstaller.exe

    Note: Make sure to exclude subfolders. Some solutions automatically exclude subfolders, but others require explicit notation.

  2. Exclude the SentinelOne Agent kernel-mode driver, service, and dynamic library:

    • Kernel-Mode driver: SentinelMonitor.sys

    • Windows Service: SentinelAgent.exe

    • 32-bit DLL: InProcessClient32.dll

    • 64-bit DLL: InProcessClient64.dll


Related Articles

  • Integrating with 3rd Party Syslog and Threat Detection Platforms
    Read More
  • How to Generate a Capture Client (SentinelOne) API Key Using a Service User
    Read More
  • Integrating SonicWall Capture Client with SonicWall Firewalls
    Read More
not finding your answers?