Is it normal for FSDIAG.exe to run wmic.exe, gpresult.exe, ipconfig.exe and schtask.exe
We got a High risk alert from EDR where FSDIAG.EXE (C:\Program Files (x86)\F-Secure\PSB\diagnostics\fsdiag.exe) is running wmicm, gpresult, ipconfig and schtask exes.
Is this normal behaviour for FSDIAG.exe?
Answers
-
Here is the Commanfd line for FSDIAG.exe:
"C:\Program Files (x86)\F-Secure\PSB\diagnostics\fsdiag.exe" --filters "basic/*,firewall/*,gpo/*,network/*,win/*" --silent --out "C:\ProgramData\F-Secure\Upload\wsdiag.zip"0 -
Hi @IT_Guy81 ,
It's normal that it runs these tools.
To whitelist these detections, you may try the following:
- Log in to the Elements Security Center at here.
- Select the Endpoint Detection and Response section in the leftmost navigation bar in Elements Security Center.
- Go to Broad Context Detections tab.
- Select the BCD ID that require whitelisting.
- Click "Update status" option at bottom page.
- Select "Closed" from drop down menu, then select reason as "False positive"
- Click "Update" option.
1 -
The FSdiag runs discovery commands and scripts to know the environment the endpoint is in, so this is not weird behavior. It's good that it does not trust fsdiag by default, since there are also antivirus vendors whos drivers for example are used for evasion. This way EDR can always check the behavior. Bummer if you run auto isolation on HIGH though 😁
3 -
Hi @IT_Guy81 tagging you for visibility with regards to @MartijnAVT comment.
1
Categories
- All Categories
- 3.5K WithSecure Community
- 3.5K Products
- Get Support