Kaspersky Endpoint Security 12.8 for Windows

Example 4. Excluded registry modifications

To exclude registry modification events from telemetry, open the EDR telemetry exclusions window on the Excluded registry changes tab and add a registry key.

Kaspersky Endpoint Security combines rule triggering criteria with a logical AND.

If an application frequently modifies its registry values and you want to exclude these registry modification events from telemetry, add the registry key and the executable file of the application to telemetry exclusions.

Specify the settings as follows:

  • Operation type: Modify;
  • Path: HKEY_LOCAL_MACHINE\SOFTWARE\SimonTatham\PuTTY64;
  • Full path: C:\Program Files\PuTTY\putty.exe;
  • SHA256: 64F7A36C01E79CD4B041E8A8607DFF06D5B606D36E3DFF9CFB5FFFA22D14D34.