Your antivirus scanner or EDR solution flags the octoja agent or a check application as a threat and blocks, quarantines, or deletes the file—whether during installation, an update or rollout, or only at runtime.
Consequence: The agent cannot be installed, updated, or started; individual checks do not return any values; and in persistent cases, numerous alerts are generated in the AV console.
Affected components include the octoja agent (Octo.Tentacle, including Octo.Tentacle.Worker.exe), the check applications (Octo.Checks.<Vendor>.exe), and the agent installer.
Currently Affected Products
Securepoint Antivirus Pro: blocks the check applications. Simply excluding the process is not enough; only excluding the entire octoja folder helps.
WatchGuard EDR/EPDR: In “Blocked” mode, everything that has not yet been classified as “Goodware” is blocked. This is not a classic false positive, but rather the default setting: Every new agent version and every Octo.Checks.*.exe file must first be classified. Audit mode does not block anything and performs classification in the background. Once a file is approved, this applies to all customers of that vendor.
ESET: Reports the agent or a check application. Adding an exception in the real-time scan helps; the files are located in Program Files and ProgramData.
Bitdefender is not currently generating any alerts.
Why this happens
The check applications read system states and are not widely used → this causes some heuristics to trigger.
What you can do
Exclude the entire octoja folder, including all versioned subfolders → not just the process or a single .exe file.
Set the exception before you roll out or update.
Restore any files that have already been quarantined and add them as exceptions.
For zero-day/blocked EDR: Use audit mode or classify the files in advance on a test system.
Report the detection as a false positive to the vendor.
Deploy the exceptions centrally via the AV/EDR console.