Getting StartedUpdated September 3, 20263 min read
Other EDR and antivirus exclusions for TAO
Generic exclusion checklist for Carbon Black, Sophos, Symantec, Trend Micro, and other AV/EDR products coexisting with Trustity TAO.
Other EDR and antivirus exclusions for TAO
If your environment uses an endpoint product without a dedicated Trustity KB page (for example VMware Carbon Black, Sophos, Symantec / Broadcom, Trend Micro, Kaspersky, ESET, Malwarebytes, or a regional AV), use this checklist with the shared object list in TAO antivirus and EDR exclusions.
Trustity cannot document every vendor console. Your endpoint-security owner should translate the objects below into that product's exclusion, allowlist, or interoperability policy.
Objects to exclude or allow
Windows paths
C:\Program Files\Trustity\TAO\C:\ProgramData\Trustity\TAO\C:\ProgramData\Trustity\
Windows processes
tao-agent.exetao-gui.exetao-tray.exetao-lock.exetao-zerodevice.exeTrustity-Agent-Setup.exe
Windows service
TrustityAgent
Linux (when TAO Linux is in scope)
- State directory
/var/lib/trustity/tao/ - Service
trustity-tao - Process / CLI
tao-agent
How to apply (any vendor)
- Open the central policy console (not only a local agent UI) for the pilot device group.
- Create an exclusion / allow / interoperability rule set named for Trustity TAO.
- Add path exclusions first (highest compatibility across products).
- Add process or hash allowlisting only if your product requires it - prefer paths so future TAO builds do not break on hash change.
- Allow the
TrustityAgentservice to start at boot without interactive block prompts. - Deploy the policy, confirm it reached agents, then install TAO from Cloud Portal → Deployment.
- Validate with
sc query TrustityAgent(Windows) orsudo systemctl status trustity-tao(Linux) and portal Online status.
Application control / AppLocker / WDAC
If you also enforce application allowlisting:
- Sign and/or publisher-rule the Trustity binaries when your program requires it.
- Allow
Trustity-Agent-Setup.exefrom the approved Deployment package location used by Intune/SCCM. - Retest after every TAO version bump on a pilot ring.
When to contact Trustity Support
Escalate with:
- Vendor product name and policy type (AV real-time, EDR prevention, AppLocker, etc.)
- Exact blocked path or process from the vendor console
- Hostname, OS, and TAO version
- Whether exclusions were applied before or after the block
Do not include organization license keys in the ticket.
