Skip to content

Notification on Windows raises an EDR alert #3531

Open
@dr-lux

Description

@dr-lux

Describe the problem

I got a Windows workstation with Bitdefender installed. The MDR service raised me an alert about a Powershell scripts fyne-NetBird-notify-1.ps1 (seems to be a script for Notification).

Analysis result
MDR analysts received an alert from the Bitdefender agent triggered by powershell executions on the host 'MYLAPTOP'. After review, the activity was attributed to usage of NetBird notification script 'fyne-NetBird-notify-1.ps1' during the session of the user 'MYUSER'. The agent blocked the activity and additional review observed no unmitigated malicious indicators. Please review the customer recommendation provided for further details. 

I see the same issue with avast (#2931)

To Reproduce

Steps to reproduce the behavior:

  1. Use Netbird 0.38.2 on Windows.

Expected behavior

Don't have an EDR alerts when using Netbird

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions