# False positive report

**URL:** <https://discuss.elastic.co/t/false-positive-report/347155>\
**Category:** Endpoint Security\
**Created:** [November 14, 2023, 6:53pm UTC](https://discuss.elastic.co/t/false-positive-report/347155 "2023-11-14T18:53:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![armada](https://avatars.discourse-cdn.com/v4/letter/a/46a35a/32.png) [@armada](https://discuss.elastic.co/u/armada)\
**Post date:** [November 14, 2023, 6:53pm UTC](https://discuss.elastic.co/t/false-positive-report/347155/1 "2023-11-14T18:53:56Z")

</div>

Hi, we followed your advice and forwarded a false positive report to [fp\_reports@elastic.co](mailto:fp_reports@elastic.co) but have not received any response. Pls advise:  
As a result of this nonsense, Lurkit terminated our service contract and suffered losses. On what basis does it detect the virus?!

Filename; GameClient.exe

Hash (SHA256): 8793afd66ca9940634c587ba6486aba0b99e096160b53c0375a0d039b15249bf

VirusTotal: /gui/file/8793afd66ca9940634c587ba6486aba0b99e096160b53c0375a0d039b15249bf

---

<div class="post-metadata">

**Author:** ![JessDaubner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessdaubner/32/127561_2.png) [@JessDaubner](https://discuss.elastic.co/u/JessDaubner)\
**Post date:** [November 14, 2023, 7:32pm UTC](https://discuss.elastic.co/t/false-positive-report/347155/2 "2023-11-14T19:32:40Z")

</div>

Hello and thank you for reaching out. Our team reviews false positive submissions on a monthly basis. While we don’t guarantee that we’ll take action on each request, if we do decide to take action and treat the detection as an FP, you can expect to see an update within a month.

Please see [Submitting False Positives](https://discuss.elastic.co/t/submitting-false-positives/232322) for more details.

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [November 14, 2023, 7:46pm UTC](https://discuss.elastic.co/t/false-positive-report/347155/3 "2023-11-14T19:46:13Z")

</div>

Hello,

Just adding one more thing:

If you encounter any FPs in your environment, you can create [Endpoint Exceptions](https://www.elastic.co/guide/en/security/current/add-exceptions.html#endpoint-rule-exceptions) to resolve any alerts and avoid further alerts in the future. If you choose to go this route, make sure you create an [Endpoint Exception](https://www.elastic.co/guide/en/security/current/add-exceptions.html#endpoint-rule-exceptions), not a Rule Exception.

I see that file is signed. Exceptions can be made by signer, which will exclude all files signed by that entity.

Regards,  
Gabriel

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2023, 7:46pm UTC](https://discuss.elastic.co/t/false-positive-report/347155/4 "2023-12-12T19:46:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
