- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-21-2026 02:48 PM
Hi everyone,
I'm observing inconsistent detection behavior in Cortex XDR during weekly on-demand scans related to the AnyDesk application.
On some endpoints, AnyDesk is detected as "Suspicious executable detected", while on others no alert is generated, even though the application is present.
One common pattern we observed is that the alerts are triggered when AnyDesk is executed from the following path:
C:\Users\user123\Downloads\AnyDesk.exe
Additionally, the file hash appears to be the same across both detected and non-detected endpoints.
Why is this detection triggered on some machines while not triggered on others?
03-23-2026 07:21 AM
Hello @M.Erkenci ,
Greetings for the day.
Inconsistent detection behavior for the AnyDesk application during on-demand or periodic scans—especially when the file hash is identical across endpoints—is usually caused by differences in policy, verdict handling, or alert visibility rather than the file itself.
If the WildFire verdict for the AnyDesk hash is “Unknown” or “Benign – Low Confidence”, the Cortex XDR agent may rely on Local Analysis.
AnyDesk is often classified as grayware / PUA (Potentially Unwanted Application).
Differences in this setting across profiles will directly cause inconsistent detections.
Cortex XDR uses regional WildFire verdicts.
This can lead to different detection outcomes across geographically distributed endpoints.
Detection may still occur, but alerts can be hidden.
Executables can be flagged based on signer trust.
Files executed from higher-risk directories are more likely to be flagged.
Examples:
C:\Users\<user>\DownloadsSame file in:
Review profiles assigned to affected vs. unaffected endpoints:
Navigate to:
Check for rules affecting:
If inconsistency persists:
trapsd.log for:
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

