Adding Threats to Exclusions

Adding Threats to Exclusions

If you get a threat that you know is not malicious, you can add it to your exclusions so that it is no longer reported as a threat. This helps reduce distractions by preventing false positives in the future. If you decide the threat may be malicious later, you can also remove the threat from the exclusions.

When you add a threat to the exclusions, you're adding the threat's Hash to the list. A threat on the exclusions list is allowed for all endpoints in the site where you allowed the threat.

To add a threat to exclusions
  1. In Barracuda XDR Dashboard, click Intelligence > Endpoint Security.

  2. In the All Threats table, click the row of the threat you want to add to an Allow List.

  3. In the top right corner, click Unquarantine and Add to Exclusions.

    Unquarantine and add to exclusions.png
  4. Click Confirm.

  • To view the exclusion list, go to Administration > Exclusions.

  • Additional exclusion types and scopes for threats are available. For more information, contact the SOC.