Exploit mitigation exclusions: variables
You can use variables when you exclude applications from checking for exploits.
Variables
Variable |
Example |
---|---|
$ |
All available drives. For example,$\app.exe excludes app.exe on drive C:, drive D:, etc. |
$admintools |
C:\Users\<user>\Administrative Tools C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools CSIDL_COMMON_ADMINTOOLS |
$appdata |
C:\Users\<user>\AppData\Local C:\Users\<user>\AppData\Roaming CSIDL_COMMON_APPDATA FOLDERID_LocalAppDataLow |
$cache |
C:\Users\<user>\Cache C:\Users\<user>\AppData\Local\Microsoft\Windows\INetCache CSIDL_INTERNET_CACHE |
$clickonce |
C:\Users\<user>\AppData\Local\Apps\2.0\17NXGR82.QZW\OM7PJJ9G.3YE\cust...app_234e |
$commonprogramfiles |
C:\Program Files (x86)\Common Files\ C:\Program Files\Common Files |
$contacts |
C:\users\<user>\Contacts FOLDERID_Contacts |
$desktop |
C:\Users\<user>\Desktop CSIDL_COMMON_DESKTOPDIRECTORY |
$downloads |
C:\Users\<user>\Downloads FOLDERID_Downloads |
$favorites |
C:\Users\<user>\Favorites |
$fonts |
C:\Windows\Fonts C:\Users\<user>\Fonts CSIDL_FONTS |
$links |
C:\Users\<user>\Links FOLDERID_Links |
$music |
C:\Users\<user>\My Music |
$nethood |
%USERPROFILE%\Appdata\Roaming\Microsoft\Windows\Network Shortcuts C:\Users\<user>\NetHood |
$personal |
C:\Users\<user>\My Documents |
$pictures |
C:\Users\<user>\My Pictures |
$printhood |
%USERPROFILE%\Appdata\Roaming\Microsoft\Windows\Printer Shortcuts C:\Users\<user>\PrintHood |
$profile |
C:\Users\<user> |
$programfiles |
C:\Program Files (x86) C:\Program Files |
$programs |
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs C:\Users\<user>\Programs CSIDL_COMMON_PROGRAMS |
$sendto |
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo C:\Users\<user>\SendTo |
$startmenu |
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu C:\Users\<user>\StartMenu |
$startup |
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\Users\<user>\Startup CSIDL_COMMON_STARTUP |
$system32 |
C:\Windows\system32 C:\Windows\SysWOW64 |
$temp |
C:\Windows\Temp %TEMP% |
$templates |
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates C:\Users\<user>\Templates |
$video |
C:\Users\<user>\My Video |
$windows |
C:\Windows CSIDL_WINDOWS |
$winsxs |
C:\Windows\winsxs\*\ |