CrowdStrike Falcon exclusions for TAO
Coordinate CrowdStrike Falcon IOA / ML exclusions for Trustity TAO paths and processes during install and steady-state.
CrowdStrike Falcon exclusions for TAO
CrowdStrike Falcon and Trustity TAO often coexist. Falcon may flag a new privileged agent during first install or silent update. Use the shared list in TAO antivirus and EDR exclusions, then apply Falcon-side allowlisting through your Falcon administrator.
Trustity does not control Falcon console UI labels. Treat the steps below as the intent your Falcon admin should implement, not as a pixel-perfect walkthrough for every Falcon release.
What to allow
Paths
C:\Program Files\Trustity\TAO\C:\ProgramData\Trustity\TAO\C:\ProgramData\Trustity\
Processes / image files
tao-agent.exetao-gui.exetao-tray.exetao-lock.exetao-zerodevice.exeTrustity-Agent-Setup.exe
Service
- Windows service
TrustityAgent
Falcon admin checklist
- Identify detections or Prevention policy hits that reference Trustity / TAO /
tao-*.exeduring pilot. - Add machine learning / sensor visibility exclusions (or your tenant's equivalent allowlist) for the paths above on the pilot host group.
- Where your process allows it, add IOA / custom IOA exceptions only for confirmed false positives - do not blanket-disable prevention for the whole host group.
- Allow the
TrustityAgentservice to start without blocking child process creation for VisionX helpers (tao-lock.exe, session UI). - Re-deploy TAO from Cloud Portal → Deployment after the Falcon policy is assigned.
Install timing
Preferred order:
- Falcon exclusion policy reaches the host group.
- Install or upgrade TAO.
- Validate service + portal Online status.
If TAO was installed first and Falcon quarantined binaries, restore from Falcon quarantine / detections, confirm exclusions, then repair with a clean Setup from Deployment.
Validation
sc query TrustityAgent
Confirm RUNNING, tray/GUI shows the expected organization, and Managed devices lists a recent heartbeat.
