Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Package Issue]: ZAP.ZAP detected by Microsoft Defender Antivirus as PUA #153873

Closed
2 tasks done
ksast opened this issue May 16, 2024 · 17 comments
Closed
2 tasks done

[Package Issue]: ZAP.ZAP detected by Microsoft Defender Antivirus as PUA #153873

ksast opened this issue May 16, 2024 · 17 comments
Labels
Area-External Issue-Bug It either shouldn't be doing this or needs an investigation.

Comments

@ksast
Copy link

ksast commented May 16, 2024

Please confirm these before moving forward

  • I have searched for my issue and not found a work-in-progress/duplicate/resolved issue.
  • I have not been informed if the issue is resolved in a preview version of the winget client.

Category of the issue

Other

Brief description of your issue

The following package upgrade command triggered an alert coming from Microsoft Defender Antivirus:
"winget.exe" upgrade -e ZAP.ZAP --version 2.15.0 --silent --accept-package-agreements --accept-source-agreements --log C:\path\to\logfile.log

The alert is named "'Packunwan' unwanted software was prevented".
Maybe the 2.15.0 package of ZAP.ZAP is malicious.

Steps to reproduce

Try to execute the command from the description on a client that is protected by Microsoft Defender Antivirus.

Actual behavior

Defender quarantines the file ZAP_2_15_0_windows.exe as well as a tmp file.

Expected behavior

Download and install a safe package.

Environment

Windows Package Manager v1.7.11261
Copyright (c) Microsoft Corporation. All rights reserved.

Windows: Windows.Desktop v10.0.22621.3447
System Architecture: X64
Package: Microsoft.DesktopAppInstaller v1.22.11261.0

Winget Directories
-----------------------------------------------------------------------------------------------------------------------
Logs                               %LOCALAPPDATA%\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Diag…
User Settings                      %LOCALAPPDATA%\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\sett…
Portable Links Directory (User)    %LOCALAPPDATA%\Microsoft\WinGet\Links
Portable Links Directory (Machine) C:\Program Files\WinGet\Links
Portable Package Root (User)       %LOCALAPPDATA%\Microsoft\WinGet\Packages
Portable Package Root              C:\Program Files\WinGet\Packages
Portable Package Root (x86)        C:\Program Files (x86)\WinGet\Packages
Installer Downloads                %USERPROFILE%\Downloads

Links
---------------------------------------------------------------------------
Privacy Statement   https://aka.ms/winget-privacy
License Agreement   https://aka.ms/winget-license
Third Party Notices https://aka.ms/winget-3rdPartyNotice
Homepage            https://aka.ms/winget
Windows Store Terms https://www.microsoft.com/en-us/storedocs/terms-of-sale

Admin Setting                             State
--------------------------------------------------
LocalManifestFiles                        Disabled
BypassCertificatePinningForMicrosoftStore Disabled
InstallerHashOverride                     Disabled
LocalArchiveMalwareScanOverride           Disabled

Screenshots and Logs

Alert story from security.microsoft.com:
`5/15/2024 11:30:35 AM
[89624] winget.exe upgrade -e ZAP.ZAP --version 2.15.0 --silent --accept-package-agreements --accept-source-agreements --log C:\path\to\logfile.log
Command line "winget.exe" upgrade -e ZAP.ZAP --version 2.15.0 --silent --accept-package-agreements --accept-source-agreements --log C:\path\to\logfile.log
Process id 89624
Execution details Token elevation: Full, Integrity level: High
Image file path C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.22.11261.0_x64__8wekyb3d8bbwe\winget.exe
Image file SHA1 b847d7a8a8b80bc95892b8e644c574209cb1f95b
Image file creation time May 8, 2024 9:14:22 AM
Image file last modification time May 8, 2024 9:14:25 AM
PE metadata winget.exe
User domain\username
5/15/2024 11:32:31 AM
[89624] winget.exe modified file ZAP_2_15_0_windows[1].exe
Modified file sha1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\4XO3SQZ5\ZAP_2_15_0_windows[1].exe
Size 227 MB
Is PE True
Creation time May 15, 2024 11:32:00 AM
Last modified time May 15, 2024 11:32:31 AM
Is run time packed True
PE metadata ZAP_2_15_0_windows[1].exe
Remediation details Defender detected and quarantined 'PUA:Win32/Packunwan' in file 'ZAP_2_15_0_windows[1].exe', preventing attempted creation by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/15/2024 11:32:31 AM
[89624] winget.exe moved file ZAP_2_15_0_windows.exe
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Source file path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57
Size 227 MB
Is PE True
Creation time May 15, 2024 11:30:36 AM
Last modified time May 15, 2024 11:32:31 AM
Mark of the web zone identifier Trusted sites
Is run time packed True
Destination file path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\ZAP_2_15_0_windows.exe
PE metadata ZAP_2_15_0_windows.exe
Remediation details Defender detected and quarantined 'PUA:Win32/Packunwan' in file 'ZAP_2_15_0_windows.exe', preventing attempted open by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/15/2024 11:32:54 AM
winget.exe interacted with file ZAP_2_15_0_windows[1].exe
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\4XO3SQZ5\ZAP_2_15_0_windows[1].exe
Size 227 MB
Is PE True
Creation time May 15, 2024 11:32:00 AM
Last modified time May 15, 2024 11:32:31 AM
Is run time packed True
PE metadata ZAP_2_15_0_windows[1].exe
Remediation details Defender detected and quarantined 'PUA:Win32/Packunwan' in file 'ZAP_2_15_0_windows[1].exe', preventing attempted creation by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/15/2024 11:33:50 AM
winget.exe interacted with file 28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57
Size 227 MB
Remediation details Defender detected 'PUA:Win32/Packunwan' in file '28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57', during attempted creation by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
Content SHA256 55e6d3ea0d358feb32345df49bab87b8874d06b831b4294e30f06eb8934b3786
5/16/2024 11:30:34 AM
[83880] winget.exe upgrade -e ZAP.ZAP --version 2.15.0 --silent --accept-package-agreements --accept-source-agreements --log C:\path\to\logfile.log
Command line "winget.exe" upgrade -e ZAP.ZAP --version 2.15.0 --silent --accept-package-agreements --accept-source-agreements --log C:\path\to\logfile.log
Process id 83880
Execution details Token elevation: Full, Integrity level: High
Image file path C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.22.11261.0_x64__8wekyb3d8bbwe\winget.exe
Image file SHA1 b847d7a8a8b80bc95892b8e644c574209cb1f95b
Image file creation time May 8, 2024 9:14:22 AM
Image file last modification time May 8, 2024 9:14:25 AM
PE metadata winget.exe
User DOMAIN\username
5/16/2024 11:30:55 AM
winget.exe interacted with file ZAP_2_15_0_windows.exe
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\ZAP_2_15_0_windows.exe
Size 227 MB
Is PE True
Creation time May 15, 2024 11:30:36 AM
Last modified time May 15, 2024 11:32:31 AM
Mark of the web zone identifier Trusted sites
Is run time packed True
PE metadata ZAP_2_15_0_windows.exe
Remediation details Defender detected and quarantined 'PUA:Win32/Packunwan' in file 'ZAP_2_15_0_windows.exe', preventing attempted open by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
4/19/2024 7:59:49 AM
[28972] svchost.exe -k NetworkService -p
Command line svchost.exe -k NetworkService -p
Process id 28972
Execution details Token elevation: Default, Integrity level: System
Image file path C:\Windows\System32\svchost.exe
Image file SHA1 3f64c98f22da277a07cab248c44c56eedb796a81
Image file creation time May 7, 2022 7:19:30 AM
Image file last modification time May 7, 2022 7:19:30 AM
PE metadata svchost.exe
User NT AUTHORITY\NETWORK SERVICE
5/15/2024 11:32:04 AM
svchost.exe interacted with file DO1F51.tmp
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\DO1F51.tmp
Size 227 MB
Remediation details Defender detected 'PUA:Win32/Packunwan' in file 'DO1F51.tmp', during attempted creation by 'svchost.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/16/2024 3:18:51 PM
[912] smss.exe
Process id 912
Execution details Elevated
Image file path smss.exe
5/16/2024 3:19:07 PM
[1176] wininit.exe
Process id 1176
Execution details Token elevation: Default, Integrity level: System
Image file path C:\Windows\System32\wininit.exe
Image file SHA1 00596f96607680a6e9a6c488e0ef9e862c335e31
Image file creation time Dec 19, 2023 10:09:51 PM
Image file last modification time Dec 19, 2023 10:09:51 PM
PE metadata wininit.exe
User NT AUTHORITY\SYSTEM
5/16/2024 3:19:07 PM
[1248] services.exe
Process id 1248
Execution details Token elevation: Default, Integrity level: System
Image file path C:\Windows\System32\services.exe
Image file SHA1 b8cc4e83947902bf5fc7df00cad906ca6ddd5627
Image file creation time Nov 22, 2023 7:38:02 AM
Image file last modification time Nov 22, 2023 7:38:02 AM
PE metadata services.exe
User NT AUTHORITY\SYSTEM
5/16/2024 3:19:08 PM
[3240] svchost.exe -k netsvcs -p -s Schedule
Command line svchost.exe -k netsvcs -p -s Schedule
Process id 3240
Execution details Token elevation: Default, Integrity level: System
Image file path C:\Windows\System32\svchost.exe
Image file SHA1 3f64c98f22da277a07cab248c44c56eedb796a81
Image file creation time May 7, 2022 7:19:30 AM
Image file last modification time May 7, 2022 7:19:30 AM
PE metadata svchost.exe
User NT AUTHORITY\SYSTEM
5/16/2024 3:25:01 PM
[9956] winget.exe upgrade -e ZAP.ZAP --version 2.15.0 --silent --accept-package-agreements --accept-source-agreements --log C:\path\to\logfile.log
Command line "winget.exe" upgrade -e ZAP.ZAP --version 2.15.0 --silent --accept-package-agreements --accept-source-agreements --log C:\path\to\logfile.log
Process id 9956
Execution details Token elevation: Full, Integrity level: High
Image file path C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.22.11261.0_x64__8wekyb3d8bbwe\winget.exe
Image file SHA1 b847d7a8a8b80bc95892b8e644c574209cb1f95b
Image file creation time May 8, 2024 9:14:22 AM
Image file last modification time May 8, 2024 9:14:25 AM
PE metadata winget.exe
User DOMAIN\username
5/16/2024 3:26:52 PM
[9956] winget.exe modified file ZAP_2_15_0_windows[1].exe
Modified file sha1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\D0MRUZQ4\ZAP_2_15_0_windows[1].exe
Size 227 MB
Is PE True
Creation time May 16, 2024 3:26:23 PM
Last modified time May 16, 2024 3:26:52 PM
Is run time packed True
PE metadata ZAP_2_15_0_windows[1].exe
Remediation details Defender detected and quarantined 'PUA:Win32/Packunwan' in file 'ZAP_2_15_0_windows[1].exe', preventing attempted creation by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/16/2024 3:26:52 PM
[9956] winget.exe moved file ZAP_2_15_0_windows.exe
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Source file path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57
Size 227 MB
Is PE True
Creation time May 16, 2024 3:25:03 PM
Last modified time May 16, 2024 3:26:52 PM
Mark of the web zone identifier Trusted sites
Is run time packed True
Destination file path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\ZAP_2_15_0_windows.exe
PE metadata ZAP_2_15_0_windows.exe
Remediation details Defender detected and quarantined 'PUA:Win32/Packunwan' in file 'ZAP_2_15_0_windows.exe', preventing attempted open by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/16/2024 3:27:15 PM
winget.exe interacted with file ZAP_2_15_0_windows[1].exe
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\D0MRUZQ4\ZAP_2_15_0_windows[1].exe
Size 227 MB
Is PE True
Creation time May 16, 2024 3:26:23 PM
Last modified time May 16, 2024 3:26:52 PM
Is run time packed True
PE metadata ZAP_2_15_0_windows[1].exe
Remediation details Defender detected and quarantined 'PUA:Win32/Packunwan' in file 'ZAP_2_15_0_windows[1].exe', preventing attempted creation by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/16/2024 3:28:02 PM
winget.exe interacted with file 28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57
Size 227 MB
Remediation details Defender detected 'PUA:Win32/Packunwan' in file '28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57', during attempted creation by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/16/2024 3:21:23 PM
[3796] svchost.exe -k NetworkService -p
Command line svchost.exe -k NetworkService -p
Process id 3796
Execution details Token elevation: Default, Integrity level: System
Image file path C:\Windows\System32\svchost.exe
Image file SHA1 3f64c98f22da277a07cab248c44c56eedb796a81
Image file creation time May 7, 2022 7:19:30 AM
Image file last modification time May 7, 2022 7:19:30 AM
PE metadata svchost.exe
User NT AUTHORITY\NETWORK SERVICE
5/16/2024 3:26:27 PM
svchost.exe interacted with file DOC986.tmp
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\DOC986.tmp
Size 227 MB
Remediation details Defender detected 'PUA:Win32/Packunwan' in file 'DOC986.tmp', during attempted creation by 'svchost.exe'
'Packunwan' unwanted software was detected New Detected Informational
Additional related files

5/15/2024 11:32:04 AM
DO1F51.tmp
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\DO1F51.tmp
Size 227 MB
Remediation details Defender detected 'PUA:Win32/Packunwan' in file 'DO1F51.tmp', during attempted creation by 'svchost.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/15/2024 11:32:54 AM
ZAP_2_15_0_windows[1].exe
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\4XO3SQZ5\ZAP_2_15_0_windows[1].exe
Size 227 MB
Is PE True
Creation time May 15, 2024 11:32:00 AM
Last modified time May 15, 2024 11:32:31 AM
Is run time packed True
PE metadata ZAP_2_15_0_windows[1].exe
Remediation details Defender detected and quarantined 'PUA:Win32/Packunwan' in file 'ZAP_2_15_0_windows[1].exe', preventing attempted creation by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/16/2024 11:30:55 AM
ZAP_2_15_0_windows.exe
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\ZAP_2_15_0_windows.exe
Size 227 MB
Is PE True
Creation time May 15, 2024 11:30:36 AM
Last modified time May 15, 2024 11:32:31 AM
Mark of the web zone identifier Trusted sites
Is run time packed True
PE metadata ZAP_2_15_0_windows.exe
Remediation details Defender detected and quarantined 'PUA:Win32/Packunwan' in file 'ZAP_2_15_0_windows.exe', preventing attempted open by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/16/2024 3:26:27 PM
DOC986.tmp
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\DOC986.tmp
Size 227 MB
Remediation details Defender detected 'PUA:Win32/Packunwan' in file 'DOC986.tmp', during attempted creation by 'svchost.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/16/2024 3:27:15 PM
ZAP_2_15_0_windows[1].exe
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\D0MRUZQ4\ZAP_2_15_0_windows[1].exe
Size 227 MB
Is PE True
Creation time May 16, 2024 3:26:23 PM
Last modified time May 16, 2024 3:26:52 PM
Is run time packed True
PE metadata ZAP_2_15_0_windows[1].exe
Remediation details Defender detected and quarantined 'PUA:Win32/Packunwan' in file 'ZAP_2_15_0_windows[1].exe', preventing attempted creation by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
5/16/2024 3:28:02 PM
28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57
SHA1 61bb04d5af2b928491215ce990ebc46dd8b3bb3d
Path C:\Users\username\AppData\Local\Temp\WinGet\ZAP.ZAP.2.15.0\28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57
Size 227 MB
Remediation details Defender detected 'PUA:Win32/Packunwan' in file '28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57', during attempted creation by 'winget.exe'
'Packunwan' unwanted software was detected New Detected Informational
`

@ksast ksast added the Issue-Bug It either shouldn't be doing this or needs an investigation. label May 16, 2024
@microsoft-github-policy-service microsoft-github-policy-service bot added the Needs-Triage This work item needs to be triaged by a member of the core team. label May 16, 2024
@vikingnope
Copy link
Contributor

vikingnope commented May 16, 2024

I do not think this would be an issue form Winget's end since it is only a package manager which downloasd ready made files from the internet. If you were to download the same file from the website would the same issue happen?

@ksast
Copy link
Author

ksast commented May 16, 2024

I do not think this would be an issue form Winget's end since it is only a package manager which downloasd ready made files from the internet. If you were to download the same file from the website would the same issue happen?

I agree it's not related to the winget software directly, however its related to a specific package distributed via the package manager's repository. Is there a better channel to address this concern?

To answer the question, yes the same issue happens when downloading the file from https://www.zaproxy.org/download.

@vikingnope
Copy link
Contributor

vikingnope commented May 16, 2024

I mean the file downloaded through winget is from Github itself

https://github.com/microsoft/winget-pkgs/blob/master/manifests/z/ZAP/ZAP/2.15.0/ZAP.ZAP.installer.yaml

I would recommend trying to check for system updates, maybe this was solved with some security update releases were it becomes excluded since it is a fake detection

Let me see if I can somewhere where to report this

@vikingnope
Copy link
Contributor

vikingnope commented May 16, 2024

Maybe look at this: https://www.microsoft.com/en-us/wdsi/filesubmission

@ksast
Copy link
Author

ksast commented May 16, 2024

I mean the file downloaded through winget is from Github itself

https://github.com/microsoft/winget-pkgs/blob/master/manifests/z/ZAP/ZAP/2.15.0/ZAP.ZAP.installer.yaml

I would recommend trying to check for system updates, maybe this was solved with some security update releases were it becomes excluded since it is a fake detection

Let me see if I can somewhere where to report this

I have confirmed that detection signatures are up to date and the file is also detected by a few other security vendors on virustotal: https://www.virustotal.com/gui/file/28b348dd65116ddabbbbd98b7f84864a0bb0f98d656266f2f08bfd010ae51c57

How do you conclude that this is a fake detection or false positive?

If not confirmed as a false positive, I would see this as a potential supply chain attack, where a malicious file is distributed via a public package manager's repository. So correct me if I'm wrong, but such packages should not be further distributed until the case has been properly investigated.

@vikingnope
Copy link
Contributor

vikingnope commented May 16, 2024

Files are scanned thoroughly usually before being allowed to be approved and posted on winget, but it may be that it is a malware (which I highly doubt).

See here: https://github.com/microsoft/winget-pkgs/blob/master/SECURITY.md

@vikingnope
Copy link
Contributor

Also see: zaproxy/zaproxy#8488

@vikingnope
Copy link
Contributor

vikingnope commented May 16, 2024

I would recommend creating an issue on the zap proxy github and link this Issue so that we can keep track of this: https://github.com/zaproxy/zaproxy/issues

@ksast
Copy link
Author

ksast commented May 16, 2024

I would recommend creating an issue on the zap proxy github and link this Issue so that we can keep track of this: https://github.com/zaproxy/zaproxy/issues

I will, thank you.

Also see: zaproxy/zaproxy#8488

I'm not quite happy how this was handled. One guy just recommended to report it as false positive without any justification. But maybe that's just me. Thx.

@psiinon
Copy link
Contributor

psiinon commented May 16, 2024

ZAP project lead here.
We do think this is very likely to be a false positive, but we are doing due diligence

@psiinon
Copy link
Contributor

psiinon commented May 16, 2024

We are sure it is a false positive, as per zaproxy/zaproxy#8491 (comment)
But if anyone has any other evidence we can look at, or any contacts the the Microsoft Defender team then please let me know.

@vikingnope
Copy link
Contributor

@psiinon, maybe you can send an email on the email found in the docs below:

https://github.com/microsoft/winget-pkgs/blob/master/SECURITY.md

@psiinon
Copy link
Contributor

psiinon commented May 17, 2024

@vikingnope I've just done that 😁 I'll also be writing a ZAP FAQ which will explain this situation in more detail...

@psiinon
Copy link
Contributor

psiinon commented May 17, 2024

New ZAP FAQ: https://www.zaproxy.org/faq/why-does-my-antivirus-tool-flag-zap/

@stephengillie stephengillie removed the Needs-Triage This work item needs to be triaged by a member of the core team. label May 17, 2024
@mdanish-kh
Copy link
Contributor

[Policy] Area-External

@psiinon
Copy link
Contributor

psiinon commented May 21, 2024

I've had a response from the Microsoft Security Response Center.
They have confirmed it is a False Positive and that they have rolled out a fix.
I think this issue can be closed now?

@vikingnope
Copy link
Contributor

I've had a response from the Microsoft Security Response Center.
They have confirmed it is a False Positive and that they have rolled out a fix.
I think this issue can be closed now?

@psiinon , thank you for your cooperation and swift reply. We will be closing this ticket.🙂

@stephengillie or @ksast can you kindly close this ticket, please.

@ksast ksast closed this as completed May 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Area-External Issue-Bug It either shouldn't be doing this or needs an investigation.
Projects
None yet
Development

No branches or pull requests

5 participants