Cortex blocking hashes in allowed list

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex blocking hashes in allowed list

L2 Linker

Hello ,

 

Just wondering why does cortex block hashes that are already part of allow list sometimes ?

5 REPLIES 5

L3 Networker

Hello! I had a similar problem with some incidents. I created the white listing, but the process still blocked. 

The workaround was to restart the pc (and maybe to check in). 

Try it and give ma feedback if it is working for you. 

Hello ! Thanks a ton for the workaround ! This is only working on few of the system. 

L1 Bithead

We have similar problems with white-listed binaries and received the following explanation: The white listing only adds the hash to a list of static IOC, if the binary acts in a suspicious way (either live or in WildFire) it will be blocked. One solution is to always run the latest version and report false positives, the other one is creating a malware profile which excludes certain files and folders from being scanned.

 

Hi @MartinPfeil 

you can also tweak wildfire verdict if you dont agree with it, and you will get an answer from us in 2 or 3 days. 

KR,
Luis

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!