Replies: 3 comments
-
This must be a false positive. I updated Win 11 to security definition version 1.403.1363.0, downloaded the .zip file from github, extracted it with Windows 11 Explorer, right-clicked the folder and checked it with Windows Defender. No threats found. Running VirusTotal against the .zip download URL on github, I get these results: Uploading my original .zip directly to VirusTotal, I get this: And ChanSort.exe on its own: I can only GUESS why ArcSight might find something suspicious. At the time I was testing ChanSort 2023-12-18 for release, Windows Defender inside a test VM deleted ChanSort.exe with a false-positive of "Behavior:Win32/DefenseEvasion.A!ml". I reported this incident to Microsoft as I am certain it was a false-positive. |
Beta Was this translation helpful? Give feedback.
-
Did you download ChanSort_2023-12-18.zip from github or some other download site? I have no control over other websites which might offer modified / infected files for download. |
Beta Was this translation helpful? Give feedback.
-
Hi, yes I downloaded the zip from github, have tested again with a fresh download and now it seems to be clean. Maybe it was an old definition file from Defender?! Sorry for the trouble, next time I will also test with virustotal. Happy new year and thanks for your fast response. |
Beta Was this translation helpful? Give feedback.
-
Hi, in the latest release (ChanSort_2023-12-18.zip) Defender seems to found a trojaner... can you please check
Anyway, thanks for this nice helpful piece of software :-)
Beta Was this translation helpful? Give feedback.
All reactions