---
title: Scanning on Windows with EDR or antivirus
---

## Can EDR or antivirus software interfere with Windows Explorer or CLI scans?

Yes. Some EDR, antivirus, HIDS, and endpoint protection products on Windows can interfere with runZero Explorer and CLI scanner operations. Common impacts include blocked packet capture, failed raw socket operations, unstable scan behavior, and process termination.

To reduce or resolve these issues:

1. Add allowlist exceptions for runZero binaries, services, and directories used by the Explorer or CLI scanner.
2. Ensure packet capture components (including npcap/winpcap where applicable) are not blocked by endpoint security policies.
3. If your endpoint tooling supports policy modes, use a monitoring-only mode while validating scan operations.
4. In some environments, endpoint protection controls may need to be temporarily disabled on the host to confirm whether they are the root cause.
5. Re-run the scan or reinstall/restart the Explorer after policy updates.

If issues continue, collect Explorer diagnostics or CLI output and contact runZero support.
