# False Positive

**URL:** <https://discuss.elastic.co/t/false-positive/389749>\
**Category:** Elastic Security\
**Created:** [August 18, 2026, 9:40am UTC](https://discuss.elastic.co/t/false-positive/389749 "2026-08-18T09:40:11Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![jedikeeper](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jedikeeper/32/148053_2.png) [@jedikeeper](https://discuss.elastic.co/u/jedikeeper)\
**Post date:** [August 18, 2026, 9:40am UTC](https://discuss.elastic.co/t/false-positive/389749/1 "2026-08-18T09:40:11Z")

</div>

Hello,

I understand that false positives require manual analysis by malware engineers, and that you will only take action if the False Positive is officially confirmed to be 100% safe. However, please understand that end users strictly refuse to install applications that trigger any detection on VirusTotal. Furthermore, despite having already filled out the form and provided all the requested information, no action has been taken so far to resolve this reported false positive, which is actively disrupting our deployment.

Could you please provide an estimated resolution time for this case?

VT Link: [VirusTotal](https://www.virustotal.com/gui/file/f26eea959c7b899de323f622e3662e3bf7ec2be09d41424707366db1fb93dd36/detection)

Thank you

jedikeeper

2026-08-18T06:00:00Z

---

<div class="post-metadata">

**Author:** ![jedikeeper](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jedikeeper/32/148053_2.png) [@jedikeeper](https://discuss.elastic.co/u/jedikeeper)\
**Post date:** [August 19, 2026, 11:12am UTC](https://discuss.elastic.co/t/false-positive/389749/2 "2026-08-19T11:12:42Z")

</div>

It seems like this is going to take longer than expected 😭

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 19, 2026, 2:46pm UTC](https://discuss.elastic.co/t/false-positive/389749/3 "2026-08-19T14:46:56Z")

</div>

Do you have a support contract? If Yes I would recommend that you open a ticket.

This forum, while managed by elastic, is not official support.

For false positives you also need to use the form described in this post: [Submitting False Positives](https://discuss.elastic.co/t/submitting-false-positives/232322)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2026, 1:48am UTC](https://discuss.elastic.co/t/false-positive/389749/4 "2026-08-22T01:48:32Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2026, 2:18pm UTC](https://discuss.elastic.co/t/false-positive/389749/5 "2026-08-22T14:18:46Z")

</div>



---

<div class="post-metadata">

**Author:** ![jedikeeper](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jedikeeper/32/148053_2.png) [@jedikeeper](https://discuss.elastic.co/u/jedikeeper)\
**Post date:** [August 23, 2026, 7:55pm UTC](https://discuss.elastic.co/t/false-positive/389749/6 "2026-08-23T19:55:59Z")

</div>

Unfortunately, we don't have a support contract, which means opening a ticket isn't an option for us. Frankly, it doesn't make much sense to me that this forum is managed by Elastic, yet it isn't considered official support. Regarding false positives, I have already used that form in the past, but it feels like a total waste of time because no action is ever taken. Posting here on this forum is my only way to voice my dissatisfaction, so that other users can judge for themselves whether Elastic truly cares about its customers when it comes to security issues. **I will continue to post on this forum until a real solution is provided.**

**Thank you**  
jedikeeper

 ![Screenshot 2026-08-21 at 6.55.27 p.m.](https://us1.discourse-cdn.com/elastic/original/3X/5/2/524fcaf6cd9d7a8abc88d3900c5aed399d2f5870.jpeg)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 23, 2026, 9:01pm UTC](https://discuss.elastic.co/t/false-positive/389749/7 "2026-08-23T21:01:01Z")

</div>

@jedikeeper Welcome to the community.

I poked internally, lets see what comes back.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 24, 2026, 3:32pm UTC](https://discuss.elastic.co/t/false-positive/389749/8 "2026-08-24T15:32:26Z")

</div>

@jedikeeper

From internal Malware team.

> "Hey Stephen, thanks for letting us know! I have submitted a triage request just now. I will let you know what is the outcome of it.  
> ...  
> The conclusion is that it is benign and I have marked it already. It will be picked up by the next training of the model, which will be next month now.  
> ...  
> I am not sure whether InlineLookup applies to VirusTotal scores for Elastic. If it does, the hash should be shown as benign pretty soon.

No Explicit ETA, sorry.

BTW In the future if you just say

"Hey I am a 1 person SW Shop and I could really use some help.... that would probably work better than the _"Shame, Shame, Shame"_ approach.

It is not the reason I helped (and I was close to not helping and just letting it take its course), BUT I was curious and we operate on the Be Kind, Be Smart, Be Helpful motto around here.

If I get an update on the inline lookup I will post back

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 24, 2026, 9:28pm UTC](https://discuss.elastic.co/t/false-positive/389749/9 "2026-08-24T21:28:39Z")

</div>

Whalluh!

> [@jedikeeper](#):
>
> VT Link: [VirusTotal](https://www.virustotal.com/gui/file/f26eea959c7b899de323f622e3662e3bf7ec2be09d41424707366db1fb93dd36/detection)

 ![Screenshot 2026-08-24 at 2.26.35 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2eb952eadc66737a339fd530af4417dafb09d0da.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 24, 2026, 9:49pm UTC](https://discuss.elastic.co/t/false-positive/389749/10 "2026-08-24T21:49:27Z")

</div>

I notice that hash is for the previous 343 version of the software.

I downloaded and tried the latest version of the SW and it still flags.

So it is not clear to me from the link you provided if you were only interested in the previous version.

I asked a few more questions internally, that team is EMEA so will need to wait

Will let you know what I find out.
