Endpoint Detection and Response (EDR)

 View Only
  • 1.  Symantec False Positive Submission

    Posted Dec 26, 2020 05:45 PM

    Hi,

    we develop software and one of our customers experienced a problem with Symantec Endpoint Protection classifying our installer as suspicous and preventing the download.

    I tried to submit our software to Sample Submission | SymSubmission but none of the methods to provide the file were working, uploading and submitting a download link failed because of file size limitiations (our installer is 150MB) and a MD5-Hash was also rejected.

    Is there any alternative method to provide files to reporting false positive or get it whitelisted? Ideally for all Symantec security products? We would like to include this as a step in our release process.

    Thanks in advance!



  • 2.  RE: Symantec False Positive Submission

    Broadcom Employee
    Posted Dec 28, 2020 12:54 PM
    Edited by SSE-JDavis Dec 28, 2020 01:00 PM

    This post is not related to the SEDR appliance. All of the options available to you are listed on that website. Please read it carefully.

    Have you considered signing your binaries with a certificate?

    Endpoint Protection Download Insight is blocking an internally developed program
    https://knowledge.broadcom.com/external/article?articleId=155316
    ------------------------------
    Strategic Support Engineer
    Broadcom
    ------------------------------

    Hi,

    we develop software and one of our customers experienced a problem with Symantec Endpoint Protection classifying our installer as suspicous and preventing the download.

    I tried to submit our software to Sample Submission | SymSubmission but none of the methods to provide the file were working, uploading and submitting a download link failed because of file size limitiations (our installer is 150MB) and a MD5-Hash was also rejected.

    Is there any alternative method to provide files to reporting false positive or get it whitelisted? Ideally for all Symantec security products? We would like to include this as a step in our release process.

    Thanks in advance!



  • 3.  RE: Symantec False Positive Submission

    Posted Jan 05, 2021 04:29 AM
    Thanks for the reply. I carefully read and evaluated all the options on the SymSubmission Webseite. There is no way to submit our installer there, because of the file size limitations on the site.

    Our binaries are properly signed by a code signing CA and recognized by Windows as a trusted executable.

    I read through the provided KB-Article, and the remaining option is to whitelist our download location at the customer's Endpoint Protection Installation. This is suboptimal, as it requires additional action by every customer.

    With a different Antivirus company, we have the option to upload our files via ftp and get them checked and whitelisted. Is there no such option for Broadcom/Symantec?


  • 4.  RE: Symantec False Positive Submission

    Broadcom Employee
    Posted Jan 05, 2021 11:54 AM
    If your binaries are already signed, you just need to add an exception for that certificate.

    https://help.symantec.com/cs/ccd/CCD/v120715667_v129301524/Adding-Whitelist-policy-scan-exceptions?locale=EN_US

    ------------------------------
    Strategic Support Engineer
    Broadcom
    ------------------------------