# Defend exclusion by parent signature?

**URL:** <https://discuss.elastic.co/t/defend-exclusion-by-parent-signature/365075>\
**Category:** Endpoint Security\
**Created:** [August 18, 2024, 4:26am UTC](https://discuss.elastic.co/t/defend-exclusion-by-parent-signature/365075 "2024-08-18T04:26:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![FranklinFurter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/franklinfurter/32/122338_2.png) [@FranklinFurter](https://discuss.elastic.co/u/FranklinFurter)\
**Post date:** [August 18, 2024, 4:26am UTC](https://discuss.elastic.co/t/defend-exclusion-by-parent-signature/365075/1 "2024-08-18T04:26:52Z")

</div>

I recently ran into an issue where Defend is triggering on suspicious activity. Unfortunately, the suspicious activity is due to a legitimate software install that is adding itself to the windows defender exclusions directory via subprocessing powershell to add the entry. What this ends up meaning is that i can add powershell as a trusted application to allow the install, which isn't really what i want.

My question is, is there a way for me to add an exclusion or trusted application where the exclusion is basically if the parent of the application causing a specific malicious trigger has a specific validated signature then allow it? Otherwise i need to jump through hoops every time i want to update this specific software.

---

<div class="post-metadata">

**Author:** ![FranklinFurter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/franklinfurter/32/122338_2.png) [@FranklinFurter](https://discuss.elastic.co/u/FranklinFurter)\
**Post date:** [August 18, 2024, 4:27am UTC](https://discuss.elastic.co/t/defend-exclusion-by-parent-signature/365075/2 "2024-08-18T04:27:20Z")

</div>

From #Elastic Security to #Endpoint Security

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [August 19, 2024, 4:05pm UTC](https://discuss.elastic.co/t/defend-exclusion-by-parent-signature/365075/3 "2024-08-19T16:05:09Z")

</div>

> Defend is triggering on suspicious activity

Hi @FranklinFurter. You can create an [Endpoint Alert Exception](https://www.elastic.co/guide/en/security/current/add-exceptions.html#endpoint-rule-exceptions) on any field that Endpoint sends in the alert. If `process.parent.code_signature` or `process.parent.Ext.code_signature` are present, you can use them in exceptions.

When trusting signers, make sure to also check `trusted: true` as a nested condition paired with `subject_name`. A file can have multiple signers. Nested checks ensure that the two fields are validated as a tuple.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/f/ef33487223b000334d6d2dcc155e7f7b6acdd451.png)

---

<div class="post-metadata">

**Author:** ![FranklinFurter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/franklinfurter/32/122338_2.png) [@FranklinFurter](https://discuss.elastic.co/u/FranklinFurter)\
**Post date:** [August 19, 2024, 6:25pm UTC](https://discuss.elastic.co/t/defend-exclusion-by-parent-signature/365075/4 "2024-08-19T18:25:16Z")

</div>

Thanks, I'll check that out. I was under the impression that the alert exception was simply not creating an alert on the elastic server side but would still stop the process on the client side. That's not the case then?

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [August 19, 2024, 7:19pm UTC](https://discuss.elastic.co/t/defend-exclusion-by-parent-signature/365075/5 "2024-08-19T19:19:53Z")

</div>

[Rule exceptions](https://www.elastic.co/guide/en/security/current/add-exceptions.html#detection-rule-exceptions) are as you describe. [Endpoint Exceptions](https://www.elastic.co/guide/en/security/current/add-exceptions.html#endpoint-rule-exceptions) are processed on-Endpoint before potentially generating any alerts or blocking behavior.

Related [discussion](https://discuss.elastic.co/t/elastic-security-rule-exceptions-vs-endpoint-exceptions/355404/2).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2024, 7:20pm UTC](https://discuss.elastic.co/t/defend-exclusion-by-parent-signature/365075/6 "2024-09-16T19:20:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
