<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TinyTurlaV2 Service Created - False positive detection in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025195#M8173</link>
    <description>&lt;P&gt;I received an alert 2024-02-2617:21UTC for the System Restore Disabled by Registry. After that nothing. Thought I was missing something with my alerts.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2024 15:39:42 GMT</pubDate>
    <dc:creator>emapsit</dc:creator>
    <dc:date>2024-02-27T15:39:42Z</dc:date>
    <item>
      <title>TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5024861#M8158</link>
      <description>&lt;P&gt;Today we see a lot of Threat detections that detect&amp;nbsp;&lt;STRONG&gt;TinyTurlaV2 Service Created.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I just wonder if this has something to do with the False Positive Detections on Behaviorla Protection that Cisco annonsed yeasterday evening. It looks like this detections started at the same time so therefore my question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also found this question on&amp;nbsp;&lt;A href="https://www.reddit.com/r/DefenderATP/comments/1b0r63w/tinyturlav2_service/" target="_blank" rel="noopener"&gt;TinyTurlaV2 Service : r/DefenderATP (reddit.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 07:20:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5024861#M8158</guid>
      <dc:creator>Leijonbo</dc:creator>
      <dc:date>2024-02-27T07:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5024953#M8159</link>
      <description>&lt;P&gt;did anyone got a response of Cisco's them self already?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 09:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5024953#M8159</guid>
      <dc:creator>alexdeschrijver</dc:creator>
      <dc:date>2024-02-27T09:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5024956#M8160</link>
      <description>&lt;P&gt;We saw the same thing in our environment.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 09:30:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5024956#M8160</guid>
      <dc:creator>Bunged</dc:creator>
      <dc:date>2024-02-27T09:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5024958#M8161</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I just received confirmation from cisco tac support team that&amp;nbsp;TinyTurlaV2 is&amp;nbsp;a false positive detection.&lt;/P&gt;
&lt;P&gt;"The Talos has already revoked affected signature versions and the connectors should be updating with the corrected signature bundle".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 09:16:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5024958#M8161</guid>
      <dc:creator>tashe</dc:creator>
      <dc:date>2024-02-27T09:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5024997#M8162</link>
      <description>&lt;P&gt;You beat me to it. This has to stop. 50% of our endpoints are highlighted.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 11:13:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5024997#M8162</guid>
      <dc:creator>ventaran</dc:creator>
      <dc:date>2024-02-27T11:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025012#M8163</link>
      <description>&lt;P&gt;Just got confirmation this is a FalsePositive as well&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 11:12:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025012#M8163</guid>
      <dc:creator>ventaran</dc:creator>
      <dc:date>2024-02-27T11:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025058#M8164</link>
      <description>That is also a  false positive.&lt;BR /&gt;</description>
      <pubDate>Tue, 27 Feb 2024 12:44:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025058#M8164</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-02-27T12:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025070#M8165</link>
      <description>&lt;P&gt;We received notice from our Managed Service Provider who is partnered with Cisco.&amp;nbsp; They acknowledged receiving word from Cisco that these were false positives.&amp;nbsp; Cisco is supposed to be releasing an updated signature to correct the issue.&amp;nbsp; Not sure when that will be. But it has created a lot of alerts on our end.&amp;nbsp; Nerve racking.....&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:18:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025070#M8165</guid>
      <dc:creator>joe5961</dc:creator>
      <dc:date>2024-02-27T13:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025082#M8166</link>
      <description>&lt;P&gt;Has anyone else been able to trace what apps are triggering these False Positives? I was under the impression these were supposed to have been fixed 24 hours ago.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:40:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025082#M8166</guid>
      <dc:creator>J Hefner</dc:creator>
      <dc:date>2024-02-27T13:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025088#M8167</link>
      <description>&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;As long as your BP signature is updated you should be no longer receiving these false positive events. The fix was implemented yesterday but if for some reason (PC offline) you are still on the old BP signature you will continue receiving these alerts until the Signature is updated.&lt;BR /&gt;&lt;BR /&gt;You can manually update through cmd line: &lt;STRONG&gt;C:\Program Files\Cisco\AMP\Your-Connector-Version\sfc.exe -forceApdeUpdate&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;First Seen: 2024-02-26 17:33:47&lt;BR /&gt;TinyTurlaV2-ServiceCreated&lt;BR /&gt;&lt;BR /&gt;BP Signature &lt;STRONG&gt;13381&lt;/STRONG&gt; fixes TinyTurlaV2-ServiceCreated issue&lt;BR /&gt;&lt;BR /&gt;First Seen: 2024-02-26 09:28:00&lt;BR /&gt;System-Restore&lt;BR /&gt;&lt;BR /&gt;BP Signature &lt;STRONG&gt;13380&lt;/STRONG&gt; fixes the System-Restore issue&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;Hope this help....&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025088#M8167</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2024-02-27T13:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025089#M8168</link>
      <description>&lt;P&gt;It seems that affected Behavioral Protection Signature Set is version 13357. As soon as signature set is updated to this version, events start coming. Signature set version 12887 seems to be safe.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:51:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025089#M8168</guid>
      <dc:creator>hanculak</dc:creator>
      <dc:date>2024-02-27T13:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025091#M8169</link>
      <description>The fix for the System Restore reg key went out yesterday afternoon, per discussion in the Secure Endpoint Webex team&lt;BR /&gt;&lt;BR /&gt;Not sure if/when the TinyTurla fix went.&lt;BR /&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025091#M8169</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-02-27T13:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025095#M8170</link>
      <description>&lt;P&gt;According to our testing and other articles on web, &lt;STRONG&gt;sfc.exe -forceApdeUpdate&lt;/STRONG&gt; updates only Tetra engine. BP engine signature set stayed the same.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:56:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025095#M8170</guid>
      <dc:creator>hanculak</dc:creator>
      <dc:date>2024-02-27T13:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025147#M8171</link>
      <description>&lt;P&gt;Looks like our servers are overwhelmed with delayed jobs which might be the cause why the signatures are not updating. Note was just released in the portal&amp;nbsp; to confirm the same...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_3130.png" style="width: 430px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/211183i05513714A28C4F1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_3130.png" alt="Screenshot_3130.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 14:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025147#M8171</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2024-02-27T14:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025175#M8172</link>
      <description>&lt;P&gt;All configured email alerts stopped in our environment since this whole 2-false-positive mess began. Has anyone else experienced this as well? Did Cisco turn off email alerting anyone know?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 15:20:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025175#M8172</guid>
      <dc:creator>Vince3889</dc:creator>
      <dc:date>2024-02-27T15:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025195#M8173</link>
      <description>&lt;P&gt;I received an alert 2024-02-2617:21UTC for the System Restore Disabled by Registry. After that nothing. Thought I was missing something with my alerts.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 15:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025195#M8173</guid>
      <dc:creator>emapsit</dc:creator>
      <dc:date>2024-02-27T15:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025199#M8175</link>
      <description>&lt;P&gt;Refreshed my inbox and found this alert. It wasn't there an hour ago but says it's been there for 8 hours.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="emapsit_0-1709048967382.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/211193i7C1831BF61F3DD13/image-size/medium?v=v2&amp;amp;px=400" role="button" title="emapsit_0-1709048967382.png" alt="emapsit_0-1709048967382.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 15:49:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025199#M8175</guid>
      <dc:creator>emapsit</dc:creator>
      <dc:date>2024-02-27T15:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025200#M8176</link>
      <description>I also haven't gotten anything from these...&lt;BR /&gt;Though I should have.&lt;BR /&gt;My subscription is still in place.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;________________________________&lt;BR /&gt;&lt;BR /&gt;This email is intended solely for the use of the individual to whom it is addressed and may contain information that is privileged, confidential or otherwise exempt from disclosure under applicable law. If the reader of this email is not the intended recipient or the employee or agent responsible for delivering the message to the intended recipient, you are hereby notified that any dissemination, distribution, or copying of this communication is strictly prohibited.&lt;BR /&gt;If you have received this communication in error, please immediately notify us by telephone and return the original message to us at the listed email address.&lt;BR /&gt;Thank You.</description>
      <pubDate>Tue, 27 Feb 2024 15:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025200#M8176</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-02-27T15:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025208#M8177</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1095943"&gt;@emapsit&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321979"&gt;@Ken Stieers&lt;/a&gt;&amp;nbsp;. Seeing these 2 messages now:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vince3889_1-1709049215455.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/211196i5A8D00762521EA8D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Vince3889_1-1709049215455.png" alt="Vince3889_1-1709049215455.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I guess this is like 'retrospective detections' but applied to system messages? I wanna rant so bad right now, this is testing the limits of self-control. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 15:55:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025208#M8177</guid>
      <dc:creator>Vince3889</dc:creator>
      <dc:date>2024-02-27T15:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: TinyTurlaV2 Service Created - False positive detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025220#M8179</link>
      <description>I hear you...&lt;BR /&gt;I think the whole pipeline of outbound data is clogged... Events, notifications, updates, everything...&lt;BR /&gt;&lt;BR /&gt;________________________________&lt;BR /&gt;&lt;BR /&gt;This email is intended solely for the use of the individual to whom it is addressed and may contain information that is privileged, confidential or otherwise exempt from disclosure under applicable law. If the reader of this email is not the intended recipient or the employee or agent responsible for delivering the message to the intended recipient, you are hereby notified that any dissemination, distribution, or copying of this communication is strictly prohibited.&lt;BR /&gt;If you have received this communication in error, please immediately notify us by telephone and return the original message to us at the listed email address.&lt;BR /&gt;Thank You.</description>
      <pubDate>Tue, 27 Feb 2024 16:06:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/m-p/5025220#M8179</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-02-27T16:06:33Z</dc:date>
    </item>
  </channel>
</rss>

