mirror of
https://github.com/amidaware/tacticalrmm.git
synced 2026-04-26 06:55:52 +03:00
[GH-ISSUE #223] winagent-v1.1.11.exe blocked by Windows Defender #2085
Labels
No labels
In Process
bug
bug
dev-triage
documentation
duplicate
enhancement
fixed
good first issue
help wanted
integration
invalid
pull-request
question
requires agent update
security
ui tweak
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/tacticalrmm#2085
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Get-ThingsRubenMade on GitHub (Dec 27, 2020).
Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/223
Installation through the custom .exe and through PowerShell script resulted in Windows Defender acting up.
Full info from Protection History:
OS information as follows:
Windows defender information:
Probably a false positive, but would like to be able to get some remote installations done without triggering a security warning on those remote systems...
Any suggestions on how to go about this?
@dinger1986 commented on GitHub (Dec 27, 2020):
Check out the discord channel.
This unfortunately is a regular issue because essentially any RMM is a Trojan. I know the developers have this in hand and are looking into code signing, feel free to donate to this project to help with this part as it's a fairly expensive yearly charge.
If you check out the discord channel I have written a script to update tactical rmm and add in exclusions. The developers have also suggested what folders need excluded to do updates/installs.
@Get-ThingsRubenMade commented on GitHub (Dec 28, 2020):
With some pointers in discord, I've managed to solve it for me personally with above PowerShell snippet.
Figured someone else might get some use out of it~
@dinger1986 commented on GitHub (Dec 28, 2020):
You should post that back on GitHub in scripts