﻿---
title: Endpoint artifacts
description: Use endpoint artifacts to adapt Elastic Defend to your environment, including trusted applications, event filters, blocklist entries, and Elastic Endpoint exceptions.
url: https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/endpoint-artifacts
products:
  - Elastic Cloud Serverless
  - Elastic Documentation
  - Elastic Security
applies_to:
  - Serverless Security projects: Generally available
  - Elastic Stack: Generally available
---

# Endpoint artifacts
Use endpoint artifacts to adapt Elastic Defend to the software, devices, and network traffic in your environment. With artifacts, you can stop false positive alerts, avoid conflicts with other security tools, store less event data in Elasticsearch, and block applications that you know are malicious.
Each artifact type changes a different part of how Elastic Endpoint handles activity on the host. Some types prevent alerts, some prevent monitoring, and some keep Elasticsearch from storing events. Before you create an artifact, check which type fits your goal.

## How endpoint artifacts work

Keep these points in mind when you create artifacts:
- **Artifacts apply to all hosts by default**: A new artifact applies to every host running Elastic Defend. To limit it to some hosts, assign it to specific Elastic Defend integration policies instead. Elastic Endpoint exceptions support per-policy assignment only after you [opt in](/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/elastic-endpoint-exceptions#endpoint-exceptions-opt-in).
- <applies-to>Elastic Cloud Serverless: Generally available</applies-to> <applies-to>Elastic Stack: Generally available since 9.4</applies-to> **One page lists every artifact type**: Go to the **Artifacts** page, then select the tab for the artifact type that you want to manage.
- <applies-to>Elastic Stack: Preview since 9.1</applies-to> **Spaces control who can edit an artifact**: Global artifacts appear in every space. A per-policy artifact belongs to the space where you create it, and only users in that space or with the **Global artifact management** privilege can edit it. To learn more, refer to the [Spaces and Elastic Defend FAQ](/elastic/docs-builder/docs/4302/solutions/security/get-started/spaces-defend-faq#spaces-security-faq-endpoint-artifacts).


## Where to start


| Your goal                                                                                                                                                                                                     | Start here                                                                                                                                                    |
|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Compare the artifact types and find the one that fits your goal                                                                                                                                               | [Optimize Elastic Defend](https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/optimize-elastic-defend)             |
| Stop Elastic Endpoint from generating alerts for activity that you expect                                                                                                                                     | [Elastic Endpoint exceptions](https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/elastic-endpoint-exceptions)     |
| Avoid conflicts with other antivirus or endpoint security software                                                                                                                                            | [Trusted applications](https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/trusted-applications)                   |
| <applies-to>Elastic Cloud Serverless: Generally available</applies-to> <applies-to>Elastic Stack: Generally available since 9.2</applies-to> Allow specific USB storage devices to connect to protected hosts | [Trusted devices](https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/trusted-devices)                             |
| Keep Elasticsearch from storing high-volume or low-value endpoint events                                                                                                                                      | [Event filters](https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/event-filters)                                 |
| Let isolated hosts communicate with specific IP addresses                                                                                                                                                     | [Host isolation exceptions](https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/host-isolation-exceptions)         |
| Prevent known malicious applications from running                                                                                                                                                             | [Blocklist](https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/blocklist)                                         |
| Check how to enter file paths and other values for each exception type                                                                                                                                        | [Exception types and value syntax](https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/exception-types-and-syntax) |


## Next steps

After you create artifacts, you can:
- Give users the [Elastic Defend feature privileges](https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/configure-elastic-defend/elastic-defend-feature-privileges) they need to view or manage each artifact type.
- Review [endpoint protection rules](https://www.elastic.co/elastic/docs-builder/docs/4302/solutions/security/manage-elastic-defend/endpoint-protection-rules) to understand the alerts that Elastic Endpoint exceptions can prevent.