Add Troubleshooting section about antivirus false positive #1840
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
As discussed in a thread on public Slack, a user recently made us aware that our
suricata-update.exe
binary gets flagged as possible malware. Here's my attempt at writing an article to address the topic proactively or via link should it come up again with other users. In addition to pointing our own users at it, I expect I might also be able to reference it from:I admit this content was a little awkward to write. Obviously I'd prefer to not have gone into such extensive detail when describing the origin of the file i question. At the same time, just saying "don't worry, it's a false positive" would have felt sleazy (isn't that exactly what a malware-provider would say?), and saying "it's open source... go convince yourself" without some detail would have felt like a lazy attempt to distract. Given that we're open source, I figured I might as well put it all out there in the open.
In addition to our own PR review process, I'll also bring this PR to the attention of the community user that offered some initial guidance and will hold off on merging until they've had a chance to offer feedback as well.