Virus scanners and EDR solutions classify octoja binary files as false positives

Your antivirus scanner or EDR solution flags the octoja agent or a check application as a threat and blocks, quarantines, or deletes the file—whether during installation, an update or rollout, or only at runtime.
Consequence: The agent cannot be installed, updated, or started; individual checks do not return any values; and in persistent cases, numerous alerts are generated in the AV console.

Affected components include the octoja agent (Octo.Tentacle, including Octo.Tentacle.Worker.exe), the check applications (Octo.Checks.<Vendor>.exe), and the agent installer.

Currently Affected Products

  • Securepoint Antivirus Pro: blocks the check applications. Simply excluding the process is not enough; only excluding the entire octoja folder helps.

  • WatchGuard EDR/EPDR: In “Blocked” mode, everything that has not yet been classified as “Goodware” is blocked. This is not a classic false positive, but rather the default setting: Every new agent version and every Octo.Checks.*.exe file must first be classified. Audit mode does not block anything and performs classification in the background. Once a file is approved, this applies to all customers of that vendor.

  • ESET: Reports the agent or a check application. Adding an exception in the real-time scan helps; the files are located in Program Files and ProgramData.

Bitdefender is not currently generating any alerts.

Why this happens

The check applications read system states and are not widely used → this causes some heuristics to trigger.

What you can do

  1. Exclude the entire octoja folder, including all versioned subfolders → not just the process or a single .exe file.

  2. Set the exception before you roll out or update.

  3. Restore any files that have already been quarantined and add them as exceptions.

  4. For zero-day/blocked EDR: Use audit mode or classify the files in advance on a test system.

  5. Report the detection as a false positive to the vendor.

  6. Deploy the exceptions centrally via the AV/EDR console.

Please authenticate to join the conversation.

Upvoters
Status

In Progress

Board
🛠️

Known Issues

Date

19 days ago

Subscribe to post

Get notified by email when there are changes.