Skip to content

Add exclusion

POST/settings/exclusions/scanning

Endpoint API · Scanning Exclusions

Add a new scanning exclusion.

Required permissionendpoint-state:update

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.

Request body

Content type: application/json

Request body fields

valuestringrequired
Exclusion value.
typestringrequired
Scanning exclusion type.
Must be one of: path, posixPath, virtualPath, process, web, pua, detectedExploit, amsi, behavioral, journalHashingProcess, journalHashingPath.
scanModestring
Default value of scan mode is "onDemandAndOnAccess" for exclusions of type path, posixPath and virtualPath, "onAccess" for process, web, pua, amsi. Behavioral and Detected Exploits (exploitMitigation) type exclusions do not support a scan mode.
Must be one of: onDemand, onAccess, onDemandAndOnAccess.
commentstring
Comment indicating why the exclusion was created.
Must be at most 100 characters long.

Request samples

curl -X POST "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/scanning" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"value\": \"Exclusion Value\",
  \"type\": \"path\",
  \"scanMode\": \"onDemand\",
  \"comment\": \"Item is a Malware.\"
}"

import requests

response = requests.post(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/scanning",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'value': 'Exclusion Value',
    'type': 'path',
    'scanMode': 'onDemand',
    'comment': 'Item is a Malware.'},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "value": "Exclusion Value",
  "type": "path",
  "scanMode": "onDemand",
  "comment": "Item is a Malware."
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/scanning" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/scanning", strings.NewReader(`{
  "value": "Exclusion Value",
  "type": "path",
  "scanMode": "onDemand",
  "comment": "Item is a Malware."
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/scanning", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "value": "Exclusion Value",
  "type": "path",
  "scanMode": "onDemand",
  "comment": "Item is a Malware."
}),
});
const data = await response.json();
console.log(data);

Responses

201 — Scanning exclusion added.

Response fields

idstring (uuid)required
Unique ID for the scanning exclusion setting.
valuestringrequired
Exclusion value.
typestringrequired
Scanning exclusion type.
Must be one of: path, posixPath, virtualPath, process, web, pua, detectedExploit, amsi, behavioral, journalHashingProcess, journalHashingPath.
scanModestringrequired
Default value of scan mode is "onDemandAndOnAccess" for exclusions of type path, posixPath and virtualPath, "onAccess" for process, web, pua, amsi. Behavioral and Detected Exploits (exploitMitigation) type exclusions do not support a scan mode.
Must be one of: onDemand, onAccess, onDemandAndOnAccess.
descriptionstring
Exclusion description added by the system.
commentstring
Comment indicating why the exclusion was created.
lockedByManagingAccountbooleanrequired
Whether a partner manages the exclusion. 'true' means that only the partner can change or delete it.

Errors

Status Meaning
400 Bad request.
403 Forbidden. This may be due to scanning exclusions being managed at Partner/Enterprise level.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

201

{
  "id": "00000000-0000-0000-0000-000000000000",
  "value": "string",
  "type": "path",
  "scanMode": "onDemand",
  "description": "string",
  "comment": "string",
  "lockedByManagingAccount": true
}

See the guide for a narrative walkthrough of this API.