False Positive

Hello,

I understand that false positives require manual analysis by malware engineers, and that you will only take action if the False Positive is officially confirmed to be 100% safe. However, please understand that end users strictly refuse to install applications that trigger any detection on VirusTotal. Furthermore, despite having already filled out the form and provided all the requested information, no action has been taken so far to resolve this reported false positive, which is actively disrupting our deployment.

Could you please provide an estimated resolution time for this case?

VT Link: VirusTotal

Thank you

jedikeeper

2026-08-18T06:00:00Z

It seems like this is going to take longer than expected :sob:

Do you have a support contract? If Yes I would recommend that you open a ticket.

This forum, while managed by elastic, is not official support.

For false positives you also need to use the form described in this post: Submitting False Positives

Unfortunately, we don't have a support contract, which means opening a ticket isn't an option for us. Frankly, it doesn't make much sense to me that this forum is managed by Elastic, yet it isn't considered official support. Regarding false positives, I have already used that form in the past, but it feels like a total waste of time because no action is ever taken. Posting here on this forum is my only way to voice my dissatisfaction, so that other users can judge for themselves whether Elastic truly cares about its customers when it comes to security issues. I will continue to post on this forum until a real solution is provided.

Thank you
jedikeeper

@jedikeeper Welcome to the community.

I poked internally, lets see what comes back.

@jedikeeper

From internal Malware team.

"Hey Stephen, thanks for letting us know! I have submitted a triage request just now. I will let you know what is the outcome of it.
...
The conclusion is that it is benign and I have marked it already. It will be picked up by the next training of the model, which will be next month now.
...
I am not sure whether InlineLookup applies to VirusTotal scores for Elastic. If it does, the hash should be shown as benign pretty soon.

No Explicit ETA, sorry.

BTW In the future if you just say

"Hey I am a 1 person SW Shop and I could really use some help.... that would probably work better than the "Shame, Shame, Shame" approach.

It is not the reason I helped (and I was close to not helping and just letting it take its course), BUT I was curious and we operate on the Be Kind, Be Smart, Be Helpful motto around here.

If I get an update on the inline lookup I will post back

Whalluh!

I notice that hash is for the previous 343 version of the software.

I downloaded and tried the latest version of the SW and it still flags.

So it is not clear to me from the link you provided if you were only interested in the previous version.

I asked a few more questions internally, that team is EMEA so will need to wait

Will let you know what I find out.