Allow the CSE app in your Anti-Virus (AV) or Endpoint Detection Response (EDR) Solutions

Configure your AV or EDR solutions to allowlist the CSE app
Updated On: Jul 21, 2026

Overview

In some cases, an Anti-Virus (AV) or EDR solution might interfere with the Cloud Secure Edge (CSE) app because of how they interpret the app's behaviour during installation or runtime. EDR and AV tools can flag behaviour that resembles attacks: since the CSE app is running background services, creating and modifying system files, intercepting network traffic, and maintaining a persistent connection to a cloud service, these actions can signal suspicious behaviour, especially if the EDR/AV tool doesn't recognize the signing certificate or publisher.

Allow-listing the CSE app in your AV/EDR tool informs the tool that the CSE app software can be trusted and should be ignored during scans or behavioural analysis. This guide lays out the exclusions for each OS, grouped by app version: version 4.0.0 or later and legacy versions before 4.0.0.

Individual process exclusions are subject to change between app versions. Wherever your AV/EDR tool supports it, use the wildcard folder exclusion rather than listing individual binaries — it keeps working across app updates and covers new binaries automatically. List individual binaries only if your tool cannot use a wildcard, and re-check them after upgrading the app.

Version 4.0.0 or later

Recommended: use a wildcard folder exclusion. Exclude the entire CSE application folder with a wildcard:

  • Windows: %ProgramFiles%/SonicWall Cloud Secure Edge/*
  • macOS: /Applications/SonicWall Cloud Secure Edge.app/*
  • Linux: /opt/SonicWall Cloud Secure Edge/*

If your AV/EDR tool cannot use a wildcard and requires individual binaries, use the list below for your platform.

Legacy versions before 4.0.0

These apply to CSE desktop app versions 3.28.1 or earlier (the Banyan-branded app). A wildcard folder exclusion works here too — %ProgramFiles%/Banyan/* (Windows), /Applications/Banyan.app/* (macOS), or /opt/Banyan/* (Linux) — and is preferred. The individual binaries are listed below if your tool requires them.