<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Frequent &amp;quot;generic.ml&amp;quot; False-Positives in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/frequent-quot-generic-ml-quot-false-positives/m-p/303867#M1274</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are a consumer software publisher, and since this year's March we're forced to continuously struggle with the mentioned frequent false-positives from your engine's side on a weekly (&lt;EM&gt;if not to say daily&lt;/EM&gt;) basis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're releasing new files (&lt;EM&gt;installers of our apps, which are many&lt;/EM&gt;) on a daily basis, and the vicious circle here looks something like the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;－&amp;nbsp;we're detecting a ‘pack’ of the false-positives from your end - tens of our files get falsely flagged by your engine each time&lt;/P&gt;&lt;P&gt;&amp;nbsp;－ we're uploading all the flagged files to our VirusTotal Monitor Collection&lt;/P&gt;&lt;P&gt;&amp;nbsp;－ you usually stop flagging the files within a day or two after that, sometimes a bit longer,&amp;nbsp;but in the mean-time - we're detecting another ‘pack’ of your false-positives again, then everything repeats&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have really lots of files, and their number is growing, so we're just not able to detect every false-positive immediately. Also, the limited storage space, provided by the VT Monitor Service, doesn't allow us to retain all our files, so we have to&amp;nbsp;cull what to upload there &lt;STRONG&gt;manually&lt;/STRONG&gt; and then upload &lt;STRONG&gt;manually&lt;/STRONG&gt; - this can't be done immediately too. As soon as we've uploaded all necessary files to the VTmonitor Collection, you're resolving the flags fairly fast, yet anyway - not immediately as well. Everything this in sum means that a lot of our customers have more than enough time to actually see the false flags. Needless to say that it isn't good for our&amp;nbsp;reputation at least.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our question is: how can we stop this from being the case? What we can actually do now is to post-deal with the problem only, but are there any&amp;nbsp;preventive actions we are able to take? Can you do something from your side to finally stop falsely flagging our files?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Mon, 16 Dec 2019 13:48:37 GMT</pubDate>
    <dc:creator>NCH_Soft</dc:creator>
    <dc:date>2019-12-16T13:48:37Z</dc:date>
    <item>
      <title>Frequent "generic.ml" False-Positives</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/frequent-quot-generic-ml-quot-false-positives/m-p/303867#M1274</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are a consumer software publisher, and since this year's March we're forced to continuously struggle with the mentioned frequent false-positives from your engine's side on a weekly (&lt;EM&gt;if not to say daily&lt;/EM&gt;) basis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're releasing new files (&lt;EM&gt;installers of our apps, which are many&lt;/EM&gt;) on a daily basis, and the vicious circle here looks something like the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;－&amp;nbsp;we're detecting a ‘pack’ of the false-positives from your end - tens of our files get falsely flagged by your engine each time&lt;/P&gt;&lt;P&gt;&amp;nbsp;－ we're uploading all the flagged files to our VirusTotal Monitor Collection&lt;/P&gt;&lt;P&gt;&amp;nbsp;－ you usually stop flagging the files within a day or two after that, sometimes a bit longer,&amp;nbsp;but in the mean-time - we're detecting another ‘pack’ of your false-positives again, then everything repeats&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have really lots of files, and their number is growing, so we're just not able to detect every false-positive immediately. Also, the limited storage space, provided by the VT Monitor Service, doesn't allow us to retain all our files, so we have to&amp;nbsp;cull what to upload there &lt;STRONG&gt;manually&lt;/STRONG&gt; and then upload &lt;STRONG&gt;manually&lt;/STRONG&gt; - this can't be done immediately too. As soon as we've uploaded all necessary files to the VTmonitor Collection, you're resolving the flags fairly fast, yet anyway - not immediately as well. Everything this in sum means that a lot of our customers have more than enough time to actually see the false flags. Needless to say that it isn't good for our&amp;nbsp;reputation at least.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our question is: how can we stop this from being the case? What we can actually do now is to post-deal with the problem only, but are there any&amp;nbsp;preventive actions we are able to take? Can you do something from your side to finally stop falsely flagging our files?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 13:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/frequent-quot-generic-ml-quot-false-positives/m-p/303867#M1274</guid>
      <dc:creator>NCH_Soft</dc:creator>
      <dc:date>2019-12-16T13:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Frequent "generic.ml" False-Positives</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/frequent-quot-generic-ml-quot-false-positives/m-p/304717#M1277</link>
      <description>&lt;P&gt;Hi, PaloAlto,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can see our topic was escalated... Thanks, but we haven't heard anything back from you for a week. Do you perhaps need us to provide you with something more in order to get this resolved a little bit more promptly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2019 12:43:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/frequent-quot-generic-ml-quot-false-positives/m-p/304717#M1277</guid>
      <dc:creator>NCH_Soft</dc:creator>
      <dc:date>2019-12-23T12:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Frequent "generic.ml" False-Positives</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/frequent-quot-generic-ml-quot-false-positives/m-p/305044#M1279</link>
      <description>&lt;P&gt;Dear PaloAlto,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've discovered new false-positives against our files: 111 in total, and 100 out of these - from your &lt;STRONG&gt;"&lt;/STRONG&gt;Palo Alto Networks (Known Signatures)&lt;STRONG&gt;"&lt;/STRONG&gt; engine (&lt;EM&gt;Paloalto - version: 1.0 - update: 20191226&lt;/EM&gt;). Kindly refer to the following screenshot:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2019-12-27 06.47.02 PAn (KS).png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23243i5E69E3A3911EF262/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2019-12-27 06.47.02 PAn (KS).png" alt="Screenshot 2019-12-27 06.47.02 PAn (KS).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;(&lt;/STRONG&gt;&lt;/EM&gt;&lt;A title="https://www.virustotal.com/en/file/f4e79cf49c4123a3f8e621d308776abef303660f990e471151b60783c5e9bbed/analysis/1577259339" href="https://www.virustotal.com/en/file/f4e79cf49c4123a3f8e621d308776abef303660f990e471151b60783c5e9bbed/analysis/1577259339" target="_blank" rel="noopener"&gt;https://www.virustotal.com/en/file/f4e79cf49c4123a3f8e621d308776abef303660f990e471151b60783c5e9bbed/analysis/1577259339&lt;/A&gt;&lt;EM&gt;&lt;STRONG&gt;)&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please do something about that, this has become quite a considerable problem for us, and it lasts too long and too invasive...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2019 09:14:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/frequent-quot-generic-ml-quot-false-positives/m-p/305044#M1279</guid>
      <dc:creator>NCH_Soft</dc:creator>
      <dc:date>2019-12-27T09:14:21Z</dc:date>
    </item>
  </channel>
</rss>

