Threat Detection and Response (TDR) is a collection of advanced malware defense tools that correlate threat indicators from Fireboxes and Host Sensors to enable real-time, automated response to stop known, unknown, and evasive threats.
As part of the TDR solution, you install TDR Host Sensors to provide endpoint protection. In some cases, the TDR Host Sensor might have conflicts with the antivirus software installed on your endpoints. To resolve this issue, you can configure exclusions in the antivirus software and in TDR.
This document includes information about the integration of a TDR Host Sensor with a host that runs Avira. It does not describe the procedure to set up Threat Detection and Response. For information about how to set up your TDR account, how to enable TDR on a Firebox, and how to install a Host Sensor, see Quick Start — Set Up Threat Detection and Response.
To avoid conflicts between the TDR Host Sensor and Avira Antivirus Pro, add these exclusions:
- Exclusions in TDR for Avira Antivirus Pro — For Windows:
- C:\Program Files (x86)\Avira\
- C:\Program Files\Avira\
- Exclusions in TDR for Avira Antivirus — For Mac:
- /Library/Application Support/Avira/
- Exclusions in Avira Antivirus for the TDR Host Sensor — For Windows:
- 64-bit Windows — C:\Program Files (x86)\WatchGuard\Threat Detection and Response\
- 32-bit Windows — C:\Program Files\WatchGuard\Threat Detection and Response\
If the Host Sensor and Avira Antivirus detect and respond to a threat at the same time, this can cause high utilization of system resources such as CPU, memory, and disk I/O.
To complete this deployment, you must have:
- An active Threat Detection and Response subscription with Host Sensor licenses
- Avira Antivirus - Business Edition — For Windows:
- Avira Antivirus 15.0.1911.1648
- Avira 220.127.116.1153
- Avira Antivirus - Business Edition — For Mac:
- Avira Antivirus Pro 18.104.22.168
- VDF version 22.214.171.124
- Engine version 126.96.36.199
The TDR and Fireware versions tested for this deployment included:
- TDR Host Sensor 188.8.131.5264
- Firebox with Fireware v12.5 or higher
The Windows test environment for this deployment included:
- Windows 7, 8.1, 10 Enterprise 64-bit Operating System
- Memory (RAM) — 8 GB
- Processor — 2 CPU Cores
The Mac test environment for this deployment included:
- macOS 10.13
- Memory (RAM) — 8 GB
- Processor — Intel Core i5
Configure Exclusions in TDR
In your TDR account, you add exclusions to manually identify paths for files and processes that you do not want Host Sensors to monitor. Before you deploy a Host Sensor on computers that have Avira Antivirus installed, add exclusions for the Avira Antivirus file paths as TDR Exclusions in your TDR account. To add the exclusions to TDR, you can either use Predefined Exclusion Sets or add the exclusions manually.
Predefined Exclusion Sets
TDR has predefined AV exclusion sets for the most common third-party AV tools. This AV tool has a predefined exclusion set available. Predefined exclusion sets include all recommended exclusions for the AV tool. TDR updates these exclusion sets as needed. For information about predefined AV exclusion sets, see Configure TDR Exclusions.
You must also add the TDR exclusions to your AV software to avoid potential conflicts.
Manually Add AV Exclusions
If you do not want to exclude all the recommended paths in a predefined exclusion set, you can add exclusions manually.
In your TDR account, add the TDR exclusions for the paths shown in the Integration Summary.
Unless otherwise noted, configure each TDR exclusion with these options, which are selected by default:
- Also exclude subfolders
- Entities to exclude: Files and Processes
To add an exclusion in TDR:
- Log in to your TDR account or managed account as a user with Operator privileges.
- Select Configuration > Exclusion.
- Click Add Exclusion.
The Add Exclusion dialog box opens.
- In the Path text box, type the path to exclude. Folders specified in an exclusion must end with a backslash.
- To apply the exception to all hosts, in the Hosts / Groups text box, specify the group All Hosts.
- Click Save & Close.
Repeat these steps to add each exclusion.
Configure Exclusions in Avira Antivirus Pro
In Avira Antivirus Pro add the exclusions to identify the paths for files and locations to exclude. To prevent conflicts between the Host Sensor and Avira Antivirus Pro, we recommend you add exclusions in Avira Antivirus Pro for the paths used by the TDR Host Sensor.
To exclude directories used by the TDR Host Sensor, add the exclusions for the paths listed in the Integration Summary.
To add an exclusion in Avira Antivirus Pro for Windows:
- Open Avira in client, click Antivirus.
- From the lower left corner, select the Settings icon.
- From the left panel, select PC Protection > Exceptions.
The Exception page appears on the right.
- In the Files and Folders to be ignored by the System Scanner and Real-Time Protection section, click ..., select the path to exclude.
- Click Add.
- Click OK.
The Avira Antivirus Pro on Mac does not support the option to add exclusions.
For information about the integration testing methodology, see TDR Testing Methodology.