Summary
Disabling scanning of certain locations may help you maintain a cleaner database avoiding scanning of locations where you know and you intend to keep old software program versions and executable files that are known to be risky, but the organization decided to keep present and unpatched anyways.
Synopsis
Many times, you would want to disable scanning for vulnerabilities at 'special' locations:
- C:\Windows\InfusedApps\Packages\...
- ....\Backup\ directory
- C:\Users\%Profile%\<YourApp>\
- E:\External\Personal\Files\....
- %AppData%
- %Temp%
- Other paths that do not correspond to your organization's deployment policies and standard procedures.
Here are several reasons why you may want/need 'Blacklist' filter to be applied:
- Prevent SVM to be flagging infused Microsoft Office versions shipped with the default OS.
- You may want to prevent SVM from injecting odd path locations where vulnerable software instances had been found because Windows Update/CCM will anyway fail to patch these files.
- You may want to prevent SVM of discovering software in Backup locations where your organization keeps old versions of programs for backward compatibility and/or legacy reasons.
- Prevent scanning user directories and local TEMP folders which usually contain a lot of irrelevant software files that SVM may mix up with the versions you are only responsible to patch.
- Keep your SVM database clean from junk data that do not focus on your work and it does not fall under the scope of assessment of actively installed programs.
Discussion
To create a simple 'Blacklist' you should navigate to Scanning/Filter Scan Results/Scan Paths
- Enable the radio button 'Blacklisting' before proceeding
- Click the 'Add Blacklist Rule' on the left of the radio buttons
- Give your rule a descriptive name that will indicate well enough what this rule is about.
- Type the installation path of the software you want to filter out from your scan results.
- Add a backslash at the end of the path ('\').
- For example ...\AppData\Local\
- Add a backslash at the end of the path ('\').
- You have the option of using the 'Site' field to apply your rule only within a given range of hosts that reside in a particular 'Site' boundary within the SVM database.
- The 'Site' grouping in SVM2018 could be an existing SCCM collection, Active Directory OU, the name of your domain, or a Custom site that you have configured yourself.
- Using the Site to filter results is a good way to consider the scope of your filter.
- The 'Site' grouping in SVM2018 could be an existing SCCM collection, Active Directory OU, the name of your domain, or a Custom site that you have configured yourself.
- Do not attempt to use Wildcharacters (*), or regular expressions as none of these would work.
- SVM requires a full path specification and listing
- Advanced search and specification of paths are not supported by SVM/Flexera.
Additional Information
It's a good idea to avoid filtering of primary directories and to be as specific as possible with regards to the path you insert. Be very specific.
This sort of filtering is 'all-inclusive' and it will prevent scanning of all sub-folders under the path you filtered out.
Example:
Filtering out 'D:\Program Files\Backup\Adobe\' when you intend to prevent scanning of 'D:\Program Files\Backup\Adobe\OldVersions\Reader\Version3.x\' is not a good idea.
You may have other versions (or programs such as Flash, or Photoshop, etc.) also filtered out, as those may be residing in another sub-categorized folder under 'D:\Program Files\Backup\Adobe\'
Related Articles
Target SVM packages with "Path Applicability" rules 11Number of Views Imported Active Directory users do not appear in All Users due to special character "_" used in User Blacklist setting 7Number of Views Some custom SAP license rules require the use of an object's database ID instead of its name 5Number of Views Deleting a file path exemption from the Use Rights & Rules tab on a license record that has associated installer evidence … 4Number of Views Deduping rules in Normalize 8Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago