Skip to content

Windows defender possible false positive #503

Open
@okleinschmidt

Description

Wazuh version Component Install type Install method Platform
4.9.2 wazuh-agent Agent Packages Windows 10

Hello,

Windows 10 Agents are experiencing an issue where Windows Defender is blocking the Agent installation due to a trojan detection. We believe this is a false positive.

The trojan, Script/Phonzy.A!ml, will be detected during the decompression process in sysmon_eid_1.ini.

thanks;
Ole

Metadata

Assignees

Labels

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions