Remote file execution - Exclude

Hi, we run screenconnect on our network, and over the weekend it must have updated itself on all endpoints.
IDR has created an investigation for every case of the update. I cant seem to find a way to exclude this executable from the ‘remote file execution’ dection. Is this possible at all?

The remote file execution alert is from the UBA detections and therefore does not have an “exception” option however you can “modify” it through the investigations.

When closing the investigation there should be an option to “modify & close” which will give you a couple options as to the scope of the modification.

Same issue here, “modify and close” does not give any usable options.