12-02-2021 04:03 AM
We are detecting that several PDFs that we share on our internal network are being detected as VIRUS.
As we have the antivirus profile enabled in a security rule the session is reset .
Does anyone know how I can avoid this?
12-02-2021 07:15 AM
Hi @Alpalo ,
If this is a false positive you should gather the PCAP from the threat log and send it to support for analysis so they can get the signature fixed. If packet capture isn't enabled then you can enable it in the security profile.
As a workaround you can create an exception until the false positive is fixed:
Hope it helps,
12-02-2021 12:27 PM
Also if its being detected as one of the 'generic' definitions, then most likely its a false positive. Happens from time to time as the generic definitions are quit broad.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!