MDR | False Positive Notifications - Powershell.exe
Incident Report for NtiretyStatus.com
Resolved
Our vendor has confirmed that the updated hash and verdict responsible for the false flagging of powershell.exe has been reversed.  Alerts for this incident are cleared within our MDR platform.
Posted Mar 22, 2024 - 19:25 UTC
Monitoring
Customers of our MDR Platform are receiving notifications of detected malicious activity. These alarms started roughly around 17:10 UTC after the backend threat library received an updated hash and verdict, flagging the detection of powershell.exe on any device. We are aware of the notifications, and verified the change with our vendor. Ntirety will be modifying the automated BIOC change to correct the false flagging.
Posted Mar 22, 2024 - 17:36 UTC
This incident affected: Security Services (Managed Detection and Response (MDR)).