02-27-2024 07:44 AM
I have 77 occurences of this this morning in AMP. Yet when I go into these systems and review the registry, it has not been changed. We don't even use system restore. Could this be a false positive?
02-27-2024 07:57 AM
02-27-2024 08:33 AM
Thanks!
02-27-2024 02:31 PM
I'm all about security, however it seems like false positives are happening more often lately. What's worse is we have automated isolation actions configured and when a false positive triggers, it makes for a bad day.
02-27-2024 05:48 PM
Please check this post for more details...
https://community.cisco.com/t5/endpoint-security/tinyturlav2-service-created-false-positive-detection/td-p/5024861/page/2
But ultimately we got hit with two False Positive events , see bellow..
First Seen: 2024-02-26 17:33:47
TinyTurlaV2-ServiceCreated
BP Signature 13381 fixes TinyTurlaV2-ServiceCreated issue
First Seen: 2024-02-26 09:28:00
System-Restore
BP Signature 13380 fixes the System-Restore issue
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide