<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False Positives with Endpoint Harmony in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/215707#M8780</link>
    <description>&lt;P&gt;Hi MikeB,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I know it is an old post but , since it's still true in 2024, you, MikeB are pointing right at it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We don't care what blade/module it is, what we need a simple button to report&amp;nbsp; false positive from any of your too many consoles.&lt;/P&gt;&lt;P&gt;I can't even see clearly from my dashboard which blade is involved&lt;/P&gt;&lt;P&gt;Aside creating a fake button that SHOULD BE sending client logs to Checkpoint from the harmony console, what did checkpoint do to ease this process for the clients?&lt;/P&gt;&lt;P&gt;Nothing personal here Mike, if you're still working at checkpoint...&lt;/P&gt;&lt;P&gt;But I think Checkpoint should spend&amp;nbsp;&lt;SPAN&gt;little less resources "spamming" their inbox&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;and more time taking notes of customer feedback and improve their product&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 May 2024 14:00:45 GMT</pubDate>
    <dc:creator>frankbt</dc:creator>
    <dc:date>2024-05-30T14:00:45Z</dc:date>
    <item>
      <title>False Positives with Endpoint Harmony</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134163#M4849</link>
      <description>&lt;P&gt;I wanted to get the communities take on this.&amp;nbsp; We've been running Endpoint in our environment for a couple of years.&amp;nbsp; We've had a lot of growing pains with Endpoint from FDE issues and windows updates to now it's False Positives.&amp;nbsp; I am constantly getting notifications of False Positives and we go through seasons where we'll have a few weeks of relief but then all of a sudden we start seeing A LOT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One we had yesterday was regarded to a setup file for an older version of Winzip that popped up out of nowhere and quarantined the file.&amp;nbsp; Today, it's a DLL to a program that runs bash on a windows system that has been there for months.&amp;nbsp; It really makes no logical sense.&lt;/P&gt;&lt;P&gt;I want to know, are we the only ones fighting this battle?&amp;nbsp; What are others doing to mitigate these besides just adding exceptions all the time because it wastes a lot of time when we come in in the morning and find emails of events that quarantined files that are not malicious?? It'seither by the forensics blade, antimalware blade, or the anti-ransomware blade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 14:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134163#M4849</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2021-11-16T14:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives with Endpoint Harmony</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134167#M4850</link>
      <description>&lt;P&gt;I will ask one of my colleagues who is real good with this product, as Im more of a firewall guy, but from what I recall, I believe there are customers doing it exact same way. though does not sound like something you should have to do constantly, specially considering the fact it could be false positive.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 15:47:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134167#M4850</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-16T15:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives with Endpoint Harmony</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134190#M4851</link>
      <description>&lt;P&gt;Thank you.&amp;nbsp; I agree rock.&amp;nbsp; It really has been an ongoing battle and it seems to happen in seasons.&amp;nbsp; We may go a couple of weeks without an event but then all of a sudden an update happens to the virus definitions or something and we start getting hits from multiple systems at times.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 20:06:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134190#M4851</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2021-11-16T20:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives with Endpoint Harmony</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134197#M4854</link>
      <description>&lt;P&gt;I emailed my colleague, so will let you know what he says.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 22:45:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134197#M4854</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-16T22:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives with Endpoint Harmony</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134199#M4855</link>
      <description>&lt;P&gt;What version of Endpoints do you have deployed? Which modules are detecting the "false positives"?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 23:21:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134199#M4855</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2021-11-16T23:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives with Endpoint Harmony</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134255#M4859</link>
      <description>&lt;P&gt;Hello Jonathan,&lt;/P&gt;
&lt;P&gt;My name is Doron and I’m the team lead of the Static Analysis and Threat Emulation teams for Harmony EndPoint.&lt;/P&gt;
&lt;P&gt;I noticed your post on CheckMates about the false positives by Anti-Malware, Anti-Ransomware and Forensicss blades.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since some files are updated after our signatures are delivered, false positives may occur from time to time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For further inspection and preventing this in the future, can you please share some additional information about the false positives you experienced and attach the Forensics reports from: C:\ProgramData\CheckPoint\DBStore\Events folder on the relevant machines?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, for these files, can you please share the files with us for further analysis with regards to why those files were detected?&lt;/P&gt;
&lt;P&gt;I have sent you an email about this, let's continue the discussion there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Doron Zuckerman&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;| Harmony EndPoint Static Analysis ML and Emulation Team Lead&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Check Point Software Technologies Ltd.&lt;/STRONG&gt;&amp;nbsp;|&amp;nbsp;M +972-54-345-3459 | &lt;A href="mailto:doronzu@checkpoint.com" target="_blank"&gt;doronzu@checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 12:29:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134255#M4859</guid>
      <dc:creator>Doron_Zuckerman</dc:creator>
      <dc:date>2021-11-17T12:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives with Endpoint Harmony</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134449#M4880</link>
      <description>&lt;P&gt;Mike right now we are running a mix of E85.40 and E86.00.&amp;nbsp; We've been having more TE, Antimalware, and BG than anything.&amp;nbsp; In the past we would have Antiransomware, but those are very far few and in between.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 22:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/134449#M4880</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2021-11-18T22:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives with Endpoint Harmony</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/215707#M8780</link>
      <description>&lt;P&gt;Hi MikeB,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I know it is an old post but , since it's still true in 2024, you, MikeB are pointing right at it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We don't care what blade/module it is, what we need a simple button to report&amp;nbsp; false positive from any of your too many consoles.&lt;/P&gt;&lt;P&gt;I can't even see clearly from my dashboard which blade is involved&lt;/P&gt;&lt;P&gt;Aside creating a fake button that SHOULD BE sending client logs to Checkpoint from the harmony console, what did checkpoint do to ease this process for the clients?&lt;/P&gt;&lt;P&gt;Nothing personal here Mike, if you're still working at checkpoint...&lt;/P&gt;&lt;P&gt;But I think Checkpoint should spend&amp;nbsp;&lt;SPAN&gt;little less resources "spamming" their inbox&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;and more time taking notes of customer feedback and improve their product&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 14:00:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/215707#M8780</guid>
      <dc:creator>frankbt</dc:creator>
      <dc:date>2024-05-30T14:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives with Endpoint Harmony</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/231842#M9619</link>
      <description>&lt;P&gt;Hallo,&lt;/P&gt;&lt;P&gt;wir haben auch so ein Problem mit False / Positve, dass sind mal Programme aus dem Systemumfeld (Microsoft) oder aber, wie aktuell, Excel Files. Nicht etwas perse alle Excel Files sondern einige wenige, die Firmenintern für Abrechnungen verwendet werden.&lt;/P&gt;&lt;P&gt;Wochenlang keine Probleme mit diesen Files dann aber ein / zwei Tage lang. Die Files werden nicht aktualisiert gespeichert sondern "repariert" und ohne Änderungen (die erfolgten durch die Anwender) weggespeichert.&lt;/P&gt;&lt;P&gt;Dann nach den ein / zwei Tagen mit diesem Problem ist wieder alles in Ordnung.&lt;/P&gt;&lt;P&gt;Der Support leifert keine Lösungen, obwohl wir dies schon in 2024 zweimal als Supportfall meldeten.&lt;/P&gt;&lt;P&gt;Die Kommunikation ist ohnehin schlecht, dauert und zieht sich. Oft bekommt man über Tage hinweg keine Rückmeldungen.&lt;/P&gt;&lt;P&gt;Gruss&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 09:57:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/231842#M9619</guid>
      <dc:creator>MRE007</dc:creator>
      <dc:date>2024-11-06T09:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: False Positives with Endpoint Harmony</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/231943#M9629</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, we also have a problem with False / Positve, which are sometimes programmes from the system environment (Microsoft) or, as is currently the case, Excel files. Not all Excel files, but a few that are used internally for billing. No problems with these files for weeks, but then for a day or two. The files are not saved updated but "repaired" and saved away without any changes (which were made by the users). Then after a day or two with this problem, everything is fine again. Support does not provide any solutions, although we already reported this twice as a support case in 2024. Communication is poor anyway, takes time and drags on. You often don't get any feedback for days. Greetings&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 08:13:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positives-with-Endpoint-Harmony/m-p/231943#M9629</guid>
      <dc:creator>MRE007</dc:creator>
      <dc:date>2024-11-07T08:13:32Z</dc:date>
    </item>
  </channel>
</rss>

