Hello everyone, I'm facing some security alerts in the software (here I would put the site's name) flagged on the website www.virus.total.com and would like to understand better how to distinguish between legitimate 'alerts' and 'false positives'.
Could someone explain to me what criteria are used to determine if an alert is genuine or if it might be a false positive?
Also, what are the best practices for handling these alerts without compromising the security of my system, and what are the direct channels for contacting for clarification, alert removal, or for engaging services related to this issue?
Thank you for your help!
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Created on 07-30-2024 10:10 AM Edited on 07-30-2024 10:11 AM
Hi Saleha,
Thank you for your response and guidance. I will proceed with the request.
Best regards.
Hi Gabriel_Leega,
Thank you for reaching out. It depends on what security UTM did the url get flagged for. I checked the url www.virus.total.com on Fortiguard webfiltering service and can see the category is business therefore I assume traffic was flagged by a different match:
https://www.fortiguard.com/webfilter
You can share the security log that matched your traffic if you find it in "Intrusion Prevention", "Application Control", SSL, Anti-Virus or other Security logs by going to "Log&Report>Security Events":
https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/876272
Thank you,
saleha
Saleha,
Thank you for your response and feedback.
Our URL www.sts.snt-mkt-automation.com has been flagged on the site www.virus.total.com.
Could you please analyze this?
Best regards.
Gabriel
Hi Gabriel,
Thank you for the reply. The url "www.sts.snt-mkt-automation.com" is listed under "Phishing" category which means the rating service have found that your website is duplicating a legitimate website with the purpose of eliciting financial, personal or other private information from the users. If this website is considered legitimate business website I recommend submitting a request to change the category for this url on the "www.virus.total.com" website. You can do the same on "fortiguard.com":
https://www.fortiguard.com/faq/wfratingsubmit
Thank you,
saleha
Created on 07-30-2024 10:10 AM Edited on 07-30-2024 10:11 AM
Hi Saleha,
Thank you for your response and guidance. I will proceed with the request.
Best regards.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.