6.10 Antivirus and EDR Exclusions
Allow the agent and its deployment scripts in your endpoint security policy
Endpoint security can block the CertKit Agent from starting, updating, or running a deployment script. Use this guide to add an exclusion (also called an allowlist or whitelist entry) for the component that was blocked. These instructions cover Windows agents.
Identify what was blocked
Run the failed deployment or update once, then find the event for that host and time in your security console. Check the process tree, file path, detection name, and action taken. A file quarantine, a blocked child process, and a blocked PowerShell script need different exclusions.
| Component | Default name or path |
|---|---|
| Windows service | certkit-agent |
| Agent executable | C:\Program Files\CertKit\bin\certkit-agent.exe |
| Configuration and log directory | C:\ProgramData\CertKit\certkit-agent\ |
| Windows PowerShell | Usually C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe; confirm the path in the event |
Confirm the service’s actual executable path and account from an elevated PowerShell prompt:
Get-CimInstance Win32_Service -Filter "Name='certkit-agent'" |
Select-Object Name, State, StartName, PathName
Use your installed path if it differs. Scope the exclusion to the hosts running CertKit. The configuration directory is listed for troubleshooting; it does not normally need a blanket exclusion.
Allowing PowerShell deployments
The agent starts powershell.exe with -NoProfile -NonInteractive -ExecutionPolicy Bypass. Post-deployment scripts are passed as base64-encoded data through standard input and executed by a fixed -Command bootstrap. This keeps deployment variables and credentials off the process command line. There is no generated .ps1 file to whitelist for these jobs.
For a blocked deployment, match the detection to the installed certkit-agent.exe and the PowerShell process it started. Include the detection’s command-line conditions where supported. Templates may also launch tools such as ssh.exe, curl.exe, or keytool.exe; check the actual process tree.
An exclusion for the agent executable does not automatically cover PowerShell or its child processes. Avoid a system-wide exclusion for powershell.exe, all .ps1 files, or the Windows temporary directory. If the product cannot limit the exception to CertKit’s activity, ask the vendor for an exception for the specific detection.
CrowdStrike Falcon
- Open the blocked event under Endpoint detections and check whether it is a machine-learning (ML) or Indicator of Attack (IOA) detection.
- For an ML detection on the agent binary, create a Machine Learning Exclusion for the installed executable path under Endpoint security > Exclusions. Assign it to the CertKit host group and enable the prevention exclusion if execution was blocked.
- For a behavioral detection on a deployment, use the event’s Create IOA exclusion action when available. Keep the specific IOA pattern and restrict its image filename and command-line conditions to the observed CertKit process chain. Use parent or grandparent conditions where the rule supports them.
- Save the exclusion for the CertKit host group and retry after policy delivery. If the detection does not offer an IOA exclusion, send the detection ID and process tree to CrowdStrike support.
ML and IOA exclusions address different detection types. Avoid a Sensor Visibility Exclusion for routine deployment failures; it reduces the telemetry available for investigation. See CrowdStrike’s exclusion types and IOA matching fields.
Palo Alto Cortex XDR
- Open the alert and identify the prevention module and causality chain.
- For a Behavioral Threat Protection alert, use Create alert exception. Keep the detected rule and constrain the exception with the CertKit causality process path, hash, or command arguments offered by the alert. Apply it to the profile used by CertKit hosts.
- For Malicious Child Process Protection, add a module exception for the installed agent as the parent and the observed PowerShell child, with execution criteria where available.
- For a file verdict on the agent executable, use the file/hash exception for the module named in the alert. A hash exception must be updated when the agent binary changes.
Depending on the console version, these settings are under Exception Configuration / Legacy Agent Exceptions or an Exceptions profile under Endpoints > Policy Management > Prevention > Profiles. Apply the profile to the affected endpoints. A PowerShell Script Files path exception does not match the agent’s scripts passed through standard input.
See Palo Alto’s module-specific exceptions and exceptions profiles.
Microsoft Defender
For an Antivirus detection on the agent file, add its full path to the file exclusions in the assigned Defender Antivirus policy. On a locally managed host, use an elevated PowerShell prompt:
Add-MpPreference -ExclusionPath 'C:\Program Files\CertKit\bin\certkit-agent.exe'
A process exclusion skips scanning files opened by that process; it is not a general permission to run the executable or its scripts. Do not add PowerShell as a process exclusion to fix a deployment. See Microsoft’s Antivirus exclusions overview.
For an Attack Surface Reduction (ASR) block, identify the rule in Defender event 1121 and configure an exclusion for that rule and the path named in the event. Prefer a per-rule exclusion in Intune or Group Policy when supported. Agent Troubleshooting includes the event-log commands and the agent’s ASR exclusion example. ASR and Antivirus exclusions are separate; see Microsoft’s ASR exclusion guidance.
For a PowerShell content or behavior detection that remains, provide the detection ID and deployment script to your security team or Microsoft support for false-positive review. The executable exclusion above does not grant blanket permission for script execution. On centrally managed hosts, make changes in the assigned policy; local exclusions may be disabled by policy.
Sophos Central / Intercept X
- Open the Threat Protection policy assigned to the CertKit servers.
- For a file-scanning detection, add a File or folder scanning exclusion for the full agent executable path.
- For an exploit detection, add a Detected Exploits (Windows/Mac) exclusion and select the actual detection. If it is not listed, use its detection ID or request one from Sophos support.
- Apply the policy to the CertKit servers and retry the deployment.
Scanning exclusions do not disable exploit checks. Keep the exception in the server policy where possible; Global Exclusions apply more broadly. See Sophos’s server policy exclusions and detected exploit exclusions.
Trend Micro Apex One
- Open Agents > Agent Management and select the CertKit computers or their group.
- For a Behavior Monitoring block, open Settings > Behavior Monitoring Settings > Exceptions. Add the full agent executable path to the Approved List and save.
- If the deployment’s child processes are still blocked, check the detection before using Settings > Trusted Program List. That list excludes the program and its child processes from Real-time Scan and Behavior Monitoring. It requires a valid digital signature and does not apply to programs in the Windows system folder.
Use the agent’s path, not PowerShell’s. If the installed agent does not meet the Trusted Program requirements, submit the file and detection logs to Trend Micro for review. See Trend Micro’s Behavior Monitoring false-positive instructions.
Verify the exclusion
Wait for the endpoint to receive the policy, then retry the action that failed. Restore a quarantined agent or rerun the installer from the Agents page if necessary.
Get-Service certkit-agent
Get-Content 'C:\ProgramData\CertKit\certkit-agent\certkit-agent.log' -Tail 100
For a deployment, check that the post-deployment command completed and that the target service presents the new certificate. Confirm that the security console shows no new prevention event. A running agent service alone does not confirm that PowerShell was allowed.
Record the detection ID and reason with the exclusion. Recheck hash-based exceptions after agent upgrades, and remove temporary exceptions once the vendor resolves the false positive.