WithSecureLabs / chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts
GNU General Public License v3.0
2.85k stars 260 forks source link

Trend Micro Antivirus removing chainsaw.exe as malicious file #47

Closed askvpb closed 2 years ago

askvpb commented 2 years ago

Trend Micro Antivirus removing chainsaw.exe as a malicious file. Is there any way we could get it reported to trend to allow it?

askvpb commented 2 years ago

https://www.virustotal.com/gui/file/ed23f2b8288cdf349b973c42c0052b0f59db8d7ccd8bc306e63f301558a01fa9/detection

FranticTyping commented 2 years ago

Hi @askvpb

Unfortunately there's very little that we can do about anti-virus services flagging chainsaw as malicious. I've just looked at the VT results again and it seems like only cynet is detecting it. I can only assume they're doing some kind of heuristics which is falsely triggering on chainsaw in this case.

This has been reported previously here: https://github.com/countercept/chainsaw/issues/12

I don't think this is an issue that I can do anything about. As such I'm going to close this issue.

Thanks!