Is there a lot to be gained from kernel level exceptions? My security engineer is willing to add PerfOp rules, but not kernel level. The PerfOp rules were shown to be minimal, if any impact, to improving performance in the past. I do not know a much about Cb App Control, but I'm figuring the performance damage is being delivered at the kernel filter driver level and not later in rule processing.