Processes protected by exploit security policy

By default, your exploit security profile protects endpoints from attack techniques that target specific processes. Each exploit protection capability protects a different set of processes that Palo Alto Networks researchers determine are susceptible to attack. The following tables display the processes that are protected by each exploit protection capability for each operating system.

### Windows processes protected by the exploit security policy

| Browser exploits protection | | |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <ul><li>[updated version of Adobe Flash Player for Firefox installed on endpoint]</li><li>browser_broker.exe</li><li>chrome.exe</li><li>firefox.exe</li></ul> | <ul><li>flashutil_activex.exe</li><li>iexplore.exe</li><li>microsoftedge.exe</li><li>microsoftedgecp.exe</li><li>opera_plugin_wrapper.exe</li></ul> | <ul><li>opera.exe</li><li>plugin-container.exe</li><li>safari.exe</li><li>webkit2webprocess.exe</li></ul> |
| **Logical exploits protection** | | |
| <ul><li>cliconfg.exe</li><li>dism.exe</li><li>dllhost.exe</li></ul> | <ul><li>excel.exe</li><li>migwiz.exe</li><li>mmc.exe</li></ul> | <ul><li>powerpnt.exe</li><li>sysprep.exe</li><li>winword.exe</li></ul> |
| **Known vulnerable processes protection** | | |
| <ul><li>7z.exe</li><li>7zfm.exe</li><li>7zg.exe</li><li>acrobat.exe</li><li>acrord32.exe</li><li>acrord32info.exe</li><li>allplayer.exe</li><li>applemobiledeviceservice.exe</li><li>apwebgrb.exe</li><li>armsvc.exe</li><li>blazehdtv.exe</li><li>bsplayer.exe</li><li>cmd.exe</li><li>eqnedt32.exe</li><li>excel.exe</li><li>flashfxp.exe</li><li>fltldr.exe</li><li>fontdrvhost.exe</li><li>foxit reader.exe</li><li>foxitreader.exe</li><li>groovemonitor.exe</li><li>hxmail.exe</li><li>i_view32.exe</li><li>infopath.exe</li></ul> | <ul><li>ipodservice.exe</li><li>itunes.exe</li><li>ituneshelper.exe</li><li>journal.exe</li><li>jqs.exe</li><li>microsoft.photos.exe</li><li>msaccess.exe</li><li>mspub.exe</li><li>mstsc.exe</li><li>nginx.exe</li><li>notepad++.exe</li><li>nslookup.exe</li><li>outlook.exe</li><li>powerpnt.exe</li><li>pptview.exe</li><li>qttask.exe</li><li>quicktimeplayer.exe</li><li>rar.exe</li><li>reader_sl.exe</li><li>realconverter.exe</li><li>realplay.exe</li><li>realsched.exe</li><li>skype.exe</li><li>skypeapp.exe</li><li>skypehost.exe</li></ul> | <ul><li>SLMail.exe</li><li>soffice.exe</li><li>sqlservr.exe</li><li>telnet.exe</li><li>unrar.exe</li><li>vboxservice.exe</li><li>vboxsvc.exe</li><li>vboxtray.exe</li><li>video.ui.exe</li><li>visio.exe</li><li>vlc.exe</li><li>vmware-authd.exe</li><li>vmware-hostd.exe</li><li>vmware-vmx.exe</li><li>vpreview.exe</li><li>vprintproxy.exe</li><li>wab.exe</li><li>w3wp.exe</li><li>winrar.exe</li><li>winword.exe</li><li>wireshark.exe</li><li>wmplayer.exe</li><li>wmpnetwk.exe</li><li>xpsrchvw.exe</li></ul> |
| **Operating system exploit protection** | | |
| <ul><li>ctfmon.exe</li><li>dllhost.exe</li><li>dns.exe</li><li>lsass.exe</li><li>msmpeng.exe</li></ul> | <ul><li>runtimebroker.exe</li><li>spoolsv.exe</li><li>svchost.exe</li><li>taskeng.exe</li></ul> | <ul><li>taskhost.exe</li><li>wmiprvse.exe</li><li>wmiprvse.exe</li><li>wwahost.exe</li></ul> |

### Mac processes protected by the exploit security policy

| Browser exploits protection | | |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <ul><li>com.apple.safariservices</li><li>com.apple.webkit.plugin</li><li>com.apple.webkit.plugin.64</li><li>com.apple.webkit.webcontent</li></ul> | <ul><li>firefox</li><li>firefox-bin</li><li>google chrome helper</li><li>google chrome</li></ul> | <ul><li>plugin-container</li><li>safari</li><li>seamonkey</li></ul> |
| **Logical exploits protection** | | |
| <ul><li>adobereader</li><li>app drive for google drive</li><li>app drop for dropbox</li><li>app for dropbox</li><li>app for facebook</li><li>app for google drive</li><li>app for googledocs</li><li>app for instagram</li><li>app for linkedin</li><li>app for youtube</li><li>com.apple.safariservices</li><li>com.apple.webkit.plugin</li><li>com.apple.webkit.plugin.64</li><li>com.apple.webkit.webcontent</li><li>document writer</li></ul> | <ul><li>firefox</li><li>firefox-bin</li><li>google chrome helper</li><li>google chrome</li><li>itunes helper</li><li>itunes</li><li>mail+ for yahoo</li><li>microsoft excel</li><li>microsoft outlook</li><li>microsoft powerpoint</li><li>microsoft remote desktop</li><li>microsoft word</li><li>miniwriterfree</li><li>parallels client</li><li>pdf reader pro free</li></ul> | <ul><li>pdf reader x</li><li>plugin-container</li><li>quicktime player</li><li>safari</li><li>seamonkey</li><li>slack</li><li>sonicwall mobile connect</li><li>textwrangler</li><li>vlc</li><li>vmware fusion services</li><li>vmware fusion</li><li>vpn shield</li><li>winmail.dat file viewer</li></ul> |
| **Known vulnerable processes protection** | | |
| <ul><li>adobereader</li><li>airmail</li><li>app drive for google drive</li><li>app drop for dropbox</li><li>app for dropbox</li><li>app for facebook</li><li>app for google drive</li><li>app for googledocs</li><li>app for instagram</li><li>app for linkedin</li><li>app for youtube</li><li>bbedit</li><li>c-lion</li><li>cisco anyconnect secure mobility client</li><li>com.apple.cloudphotosconfiguration</li></ul> | <ul><li>document writer</li><li>itunes helper</li><li>itunes</li><li>jump desktop</li><li>mail</li><li>mail+ for yahoo</li><li>messages</li><li>microsoft excel</li><li>microsoft outlook</li><li>microsoft powerpoint</li><li>microsoft remote desktop</li><li>microsoft word</li><li>miniwriterfree</li><li>parallels client</li><li>pdf reader pro free</li><li>pdf reader x</li></ul> | <ul><li>photos</li><li>photoshop</li><li>quickbooks</li><li>quicktime player</li><li>signal</li><li>slack</li><li>sonicwall mobile connect</li><li>telegram</li><li>textmate</li><li>textwrangler</li><li>thunderbird</li><li>vlc</li><li>vmware fusion services</li><li>vmware fusion</li><li>vpn shield</li><li>winmail.dat file viewer</li></ul> |

### Linux processes protected by the exploit security policy

| Known vulnerable processes protection | | |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <ul><li>anacron</li><li>apache2</li><li>authproxy</li><li>bluetoothd</li><li>charon</li><li>chronyd*</li><li>couriertcpd</li><li>cron</li><li>crond</li><li>cupsd</li><li>cyrus_pop3d</li><li>danted</li><li>dhcpd</li><li>dovecot</li><li>exim</li><li>ftpd</li><li>httpd</li><li>ibserver</li><li>identd</li><li>lighttpd</li><li>java</li><li>kamailio</li></ul><p>*chronyd is injected in some scenarios, depending on the OS.</p> | <ul><li>mailman</li><li>master</li><li>mongod</li><li>mysqld</li><li>mysqld_safe</li><li>named</li><li>ndsd</li><li>nginx</li><li>nmbd</li><li>node</li><li>nscd</li><li>php</li><li>php5-fpm</li><li>pmmasterd</li><li>pop2d</li><li>pop3d</li><li>postgres</li><li>proftpd</li><li>qmgr</li><li>rpcbind</li><li>rsync</li></ul> | <ul><li>samba</li><li>saned</li><li>sendmail</li><li>sendmail.sendmail</li><li>smartd</li><li>smbd</li><li>snmpd</li><li>squid</li><li>squid3</li><li>starter</li><li>syslog-ng</li><li>tinyproxy</li><li>vsftpd</li><li>wickedd-dhcp4</li><li>wickedd-dhcp6</li><li>winbindd</li><li>xinetd</li></ul> |