02-26-2024 11:20 PM
Today we see a lot of Threat detections that detect TinyTurlaV2 Service Created.
I just wonder if this has something to do with the False Positive Detections on Behaviorla Protection that Cisco annonsed yeasterday evening. It looks like this detections started at the same time so therefore my question.
Also found this question on TinyTurlaV2 Service : r/DefenderATP (reddit.com)
Solved! Go to Solution.
02-27-2024 05:41 PM
Looks like all the queue finally got processed as I see some BP updates in my own portal and the newest BP signature is 13411 as of right now 8:40pm EST
02-27-2024 01:10 AM
did anyone got a response of Cisco's them self already?
02-27-2024 01:14 AM - edited 02-27-2024 01:30 AM
We saw the same thing in our environment.
02-27-2024 02:47 AM - edited 02-27-2024 03:13 AM
You beat me to it. This has to stop. 50% of our endpoints are highlighted.
02-27-2024 04:44 AM
02-27-2024 01:16 AM
Hello,
I just received confirmation from cisco tac support team that TinyTurlaV2 is a false positive detection.
"The Talos has already revoked affected signature versions and the connectors should be updating with the corrected signature bundle".
02-27-2024 03:12 AM
Just got confirmation this is a FalsePositive as well
02-27-2024 05:18 AM
We received notice from our Managed Service Provider who is partnered with Cisco. They acknowledged receiving word from Cisco that these were false positives. Cisco is supposed to be releasing an updated signature to correct the issue. Not sure when that will be. But it has created a lot of alerts on our end. Nerve racking.....
02-27-2024 05:53 AM
02-27-2024 05:40 AM
Has anyone else been able to trace what apps are triggering these False Positives? I was under the impression these were supposed to have been fixed 24 hours ago.
02-27-2024 05:50 AM - edited 02-27-2024 05:50 AM
As long as your BP signature is updated you should be no longer receiving these false positive events. The fix was implemented yesterday but if for some reason (PC offline) you are still on the old BP signature you will continue receiving these alerts until the Signature is updated.
You can manually update through cmd line: C:\Program Files\Cisco\AMP\Your-Connector-Version\sfc.exe -forceApdeUpdate
First Seen: 2024-02-26 17:33:47
TinyTurlaV2-ServiceCreated
BP Signature 13381 fixes TinyTurlaV2-ServiceCreated issue
First Seen: 2024-02-26 09:28:00
System-Restore
BP Signature 13380 fixes the System-Restore issue
Hope this help....
02-27-2024 05:56 AM
According to our testing and other articles on web, sfc.exe -forceApdeUpdate updates only Tetra engine. BP engine signature set stayed the same.
02-27-2024 05:51 AM
It seems that affected Behavioral Protection Signature Set is version 13357. As soon as signature set is updated to this version, events start coming. Signature set version 12887 seems to be safe.
02-27-2024 06:48 AM
Looks like our servers are overwhelmed with delayed jobs which might be the cause why the signatures are not updating. Note was just released in the portal to confirm the same...
02-27-2024 07:20 AM
All configured email alerts stopped in our environment since this whole 2-false-positive mess began. Has anyone else experienced this as well? Did Cisco turn off email alerting anyone know?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide