Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rangh
New Contributor

Fortisandbox - FalsePositives because of Edge-Update

Hi!

For the last few days, I have been experiencing increasing issues with false positives in FortiSandbox scans.

It seems to be due to some Edge update that is running, even though I have disabled updates in the CustomVM.

The indicator is always:

'Delete system executable file: %programfiles(x86)%\microsoft\edgeupdate\install{51c6f5c0-b9db-44be-974d-ff0330e95fa6}\microsoftedgeupdatesetup_x86_1.3.187.37.exe'.

Are you aware of any way to whitelist this indicator, or is there something not mentioned in the CustomVM setup guide that I can do?

Edge-Update Services and tasks are disabled.

All the scans are made with "Chrome".

Thank you for your help!

omegle xender
1 REPLY 1
salemneaz
Staff
Staff

Try to whitelist it following the article reference given with this post;

 

https://docs.fortinet.com/document/fortisandbox/4.4.5/administration-guide/424543/allowlist-and-bloc...

Salem
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors