Hi,
I'm trying to investigate what are most likely false positive IDS events that are being outputted by our MX via syslog. Here's an example of one:
MX100 security_event security_filtering_file_scanned url=http://download.windowsupdate.com/c/msdownload/update/others/2022/02/36119907_fbffd9be78a28e77092640722a86ff95490d20b4.cab src=XX dst=XX mac=XX name='' sha256=6f8fd79ae33f21e589f4d02fdecbc9ee547c079fecc31672a0de8b12f2b05a47 disposition=malicious action=block
The SHA256 turns up no hits on Virus Total and there are no reports of this showing up in the Event Log or the Security Center. This has been happening for sometime for us on various windows machines doing updates and I haven't been able to get to the bottom of it. Any help would be appreciated.