Repository navigation
Should generate no alerts on clean system out of the box #570
Copy link
Copy link
Closed
Description
Activity
Hi @dobin,
I saw those alerts in the log file you attached in the previous issue. Definitely, false positives. We'll tune the respective rules to prevent triggering alerts by legitimate processes.
@dobin just a heads up. We've mitigated most of the FPs and rearranged some rules. Interestingly, most of the rules were triggered by the disk defrag process accessing sensitive files
- linked a pull request that will close this issuefix(rules): Eliminate false positives and harden rules #646
on Mar 8, 2026 Nice. Looking forward to 3.0.
Reacted by Nedim Šabić² and vitencellsI installed 3.0.0 on a Win 11 24H2 26100.8246
Got 3 Alerts:
{ "id": "f7b2c9d3-99e7-41d5-bb4a-6ea1a5f7f9e2", "title": "Suspicious access to the hosts file", "severity": "medium", "text": "Suspicious process C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe accessed the hosts file for potential tampering\n", "description": "Identifies suspicious process accessing the Windows hosts file for potential tampering. Adversaries can hijack the hosts files to block traffic to download/update servers or redirect the traffic to arbitrary servers under their control.\n", "labels": { "tactic.id": "TA0005", "tactic.name": "Defense Evasion", "tactic.ref": "https://attack.mitre.org/tactics/TA0005/", "technique.id": "T1562.001", "technique.name": "Impair Defenses - Disable or Modify Tools", "technique.ref": "https://attack.mitre.org/techniques/T1562/001/" }, "events": [ { "name": "CreateProcess", "category": "process", "timestamp": "2026-04-25T11:16:36.4203138+02:00", "params": { "cmdline": "\"C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe\" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --startup-read-main-dll --metrics-shmem-handle=2168,i,16137477505722183975,15207443675505419548,524288 --field-trial-handle=2384,i,7610424500120643741,16916732855647471630,262144 --variations-seed-version --pseudonymization-salt-handle=2388,i,5597598084624652117,5575474375030741751,4 --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=3288 /prefetch:11", "directory_table_base": "65d8d000", "domain": "DESKTOP-C0HF6MF", "exe": "C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe", "exit_status": "Success", "flags": "", "kproc": "ffffb20ebd6240c0", "name": "mscopilot.exe", "pid": 5540, "ppid": 9992, "real_ppid": 9992, "session_id": 2, "sid": "S-1-5-21-937184543-179303868-2836477951-1001", "start_time": "2026-04-25 11:16:36.4203138 +0200 CEST", "token_elevation_type": "LIMITED", "token_integrity_level": "MEDIUM", "token_is_elevated": false, "username": "hacker" }, "callstack": [ "fffff8068ebe0c94 unbacked!", "fffff8068ea589af unbacked!", "fffff8068eb991c2 unbacked!", "fffff8068f1458ee unbacked!", "fffff8068f145624 unbacked!", "fffff8068f0a0a21 unbacked!", "fffff8068f2c956e unbacked!", "fffff8068eebd955 unbacked!", "7ffa53823514 C:\\WINDOWS\\SYSTEM32\\ntdll.dll!ZwCreateUserProcess", "7ffa50e50c3a C:\\Windows\\System32\\KernelBase.dll!CreateProcessInternalW", "7ffa50e4e296 C:\\Windows\\System32\\KernelBase.dll!CreateProcessW", "7ffa526ac6e4 C:\\Windows\\System32\\kernel32.dll!CreateProcessW", "7ff9d9e204f3 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d9e200a5 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d9e3c36b C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d9e3adeb C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d9e3a1fb C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d90e026c C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d90e0092 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d90dfed4 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d90df6b0 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d9dda23a C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d9e16978 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d9e31138 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ffa5269e8d7 C:\\Windows\\System32\\kernel32.dll!BaseThreadInitThunk", "7ffa5374c3fc C:\\Windows\\System32\\ntdll.dll!RtlUserThreadStart" ], "proc": { "pid": 5540, "tid": 7912, "ppid": 9992, "name": "mscopilot.exe", "exe": "C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe", "cmdline": "\"C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe\" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --startup-read-main-dll --metrics-shmem-handle=2168,i,16137477505722183975,15207443675505419548,524288 --field-trial-handle=2384,i,7610424500120643741,16916732855647471630,262144 --variations-seed-version --pseudonymization-salt-handle=2388,i,5597598084624652117,5575474375030741751,4 --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=3288 /prefetch:11", "parent_name": "mscopilot.exe", "parent_cmdline": "\"C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe\" --no-startup-window --win-session-start", "sid": "S-1-5-21-937184543-179303868-2836477951-1001", "username": "hacker", "domain": "DESKTOP-C0HF6MF", "session_id": 2, "integrity_level": "MEDIUM", "is_wow64": false, "is_packaged": false, "is_protected": false, "ancestors": [ "mscopilot.exe (9992)", "explorer.exe (7592)", "userinit.exe (7264)", "winlogon.exe (7888)" ] } }, { "name": "CreateFile", "category": "file", "timestamp": "2026-04-25T11:16:36.5717914+02:00", "params": { "attributes": "", "create_disposition": "OPEN", "create_options": "OPEN_REPARSE_POINT", "file_object": "ffffb20ebd836590", "file_path": "C:\\WINDOWS\\system32\\drivers\\etc\\hosts", "irp": "ffffb20ebd447648", "share_mask": "READ|WRITE|DELETE", "status": "Success", "tid": 12348, "type": "Directory" }, "callstack": [ "fffff8068ebe0c94 unbacked!", "fffff8068ea589af unbacked!", "fffff8068eb22f86 unbacked!", "fffff80621c06d24 unbacked!", "fffff8062048baaf unbacked!", "fffff8062048b1a0 unbacked!", "fffff806204f68e0 unbacked!", "fffff8068eba953b unbacked!", "fffff8068eba94b3 unbacked!", "fffff8068f09a83b unbacked!", "fffff8068f0988da unbacked!", "fffff8068f0965e3 unbacked!", "fffff8068f09cac4 unbacked!", "fffff8068eebd955 unbacked!", "7ffa53824514 C:\\Windows\\System32\\ntdll.dll!ZwQueryFullAttributesFile", "7ffa50de331f C:\\Windows\\System32\\KernelBase.dll!GetFileAttributesExW", "7ff9da8f67cc C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess", "7ff9dad6ada2 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess", "7ff9dad6abd7 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess", "7ff9dacc4f8a C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess", "7ff9dadb8caf C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess", "7ff9dadb8c47 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess", "7ff9daabd670 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess", "7ff9d90dfd61 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d90dea3c C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d9dda23a C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d9e167e8 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ff9d9e31138 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?", "7ffa5269e8d7 C:\\Windows\\System32\\kernel32.dll!BaseThreadInitThunk", "7ffa5374c3fc C:\\Windows\\System32\\ntdll.dll!RtlUserThreadStart" ], "proc": { "pid": 5540, "tid": 12348, "ppid": 9992, "name": "mscopilot.exe", "exe": "C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe", "cmdline": "\"C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe\" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --startup-read-main-dll --metrics-shmem-handle=2168,i,16137477505722183975,15207443675505419548,524288 --field-trial-handle=2384,i,7610424500120643741,16916732855647471630,262144 --variations-seed-version --pseudonymization-salt-handle=2388,i,5597598084624652117,5575474375030741751,4 --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=3288 /prefetch:11", "parent_name": "mscopilot.exe", "parent_cmdline": "\"C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe\" --no-startup-window --win-session-start", "sid": "S-1-5-21-937184543-179303868-2836477951-1001", "username": "hacker", "domain": "DESKTOP-C0HF6MF", "session_id": 2, "integrity_level": "MEDIUM", "is_wow64": false, "is_packaged": false, "is_protected": false, "ancestors": [ "mscopilot.exe (9992)", "explorer.exe (7592)", "userinit.exe (7264)", "winlogon.exe (7888)" ] } } ] }{ "id": "a778295a-02f1-42d9-9c20-78346a7bc2c6", "title": "Suspicious protected process execution", "severity": "high", "text": "Suspicious protected process C:\\WINDOWS\\system32\\csrss.exe spawned by process C:\\WINDOWS\\System32\\smss.exe\n", "description": "Identifies unprivileged process spawning a child with protected integrity level. This \nindicates an unusual behavior that is often associated with attempts to tamper with or \nfreeze endpoint protection components.\n", "labels": { "subtechnique.id": "T1562.001", "subtechnique.name": "Disable or Modify Tools", "subtechnique.ref": "https://attack.mitre.org/techniques/T1562/001", "tactic.id": "TA0005", "tactic.name": "Defense Evasion", "tactic.ref": "https://attack.mitre.org/tactics/TA0005/", "technique.id": "T1562", "technique.name": "Impair Defenses", "technique.ref": "https://attack.mitre.org/techniques/T1562/" }, "events": [ { "name": "CreateProcess", "category": "process", "timestamp": "2026-04-25T11:16:16.3391192+02:00", "params": { "cmdline": "\\SystemRoot\\System32\\smss.exe 00000124 000000b8 winlogon.exe {F481D527-E8FA-457D-87F9-084B51C10000}", "directory_table_base": "1271de000", "domain": "NT AUTHORITY", "exe": "C:\\WINDOWS\\System32\\smss.exe", "exit_status": "Success", "flags": "PROTECTED", "kproc": "ffffb20ebb014080", "name": "smss.exe", "pid": 4936, "ppid": 440, "real_ppid": 440, "session_id": 3, "sid": "S-1-5-18", "start_time": "2026-04-25 11:16:16.3391025 +0200 CEST", "username": "SYSTEM" }, "callstack": [ "fffff8068ebe0c94 unbacked!", "fffff8068ea589af unbacked!", "fffff8068eb991c2 unbacked!", "fffff8068f1458ee unbacked!", "fffff8068f145624 unbacked!", "fffff8068f0a0a21 unbacked!", "fffff8068f2c956e unbacked!", "fffff8068eebd955 unbacked!", "7ffa53823514 C:\\Windows\\System32\\ntdll.dll!ZwCreateUserProcess", "7ffa537bd0ad C:\\Windows\\System32\\ntdll.dll!RtlNormalizeProcessParams", "7ffa537bcc54 C:\\Windows\\System32\\ntdll.dll!RtlCreateUserProcessEx", "7ff7e09c325d C:\\Windows\\System32\\smss.exe!?", "7ff7e09c4b19 C:\\Windows\\System32\\smss.exe!?", "7ff7e09c5d72 C:\\Windows\\System32\\smss.exe!?", "7ffa53738255 C:\\Windows\\System32\\ntdll.dll!RtlSetThreadSubProcessTag", "7ffa53735fe3 C:\\Windows\\System32\\ntdll.dll!RtlSetThreadSubProcessTag", "7ffa5374c412 C:\\Windows\\System32\\ntdll.dll!RtlUserThreadStart" ], "proc": { "pid": 4936, "tid": 464, "ppid": 440, "name": "smss.exe", "exe": "C:\\WINDOWS\\System32\\smss.exe", "cmdline": "\\SystemRoot\\System32\\smss.exe 00000124 000000b8 winlogon.exe {F481D527-E8FA-457D-87F9-084B51C10000}", "parent_name": "smss.exe", "parent_cmdline": "\\SystemRoot\\System32\\smss.exe", "sid": "S-1-5-18", "username": "SYSTEM", "domain": "NT AUTHORITY", "session_id": 3, "integrity_level": "SYSTEM", "is_wow64": false, "is_packaged": false, "is_protected": true, "ancestors": [ "smss.exe (440)", "System (4)", "Idle (0)", "Idle (0)" ] } }, { "name": "CreateProcess", "category": "process", "timestamp": "2026-04-25T11:16:16.3715241+02:00", "params": { "cmdline": "%SystemRoot%\\system32\\csrss.exe ObjectDirectory=\\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16", "directory_table_base": "1f837b000", "domain": "NT AUTHORITY", "exe": "C:\\WINDOWS\\system32\\csrss.exe", "exit_status": "Success", "flags": "PROTECTED", "kproc": "ffffb20eb60c6080", "name": "csrss.exe", "pid": 7032, "ppid": 4936, "real_ppid": 4936, "session_id": 3, "sid": "S-1-5-18", "start_time": "2026-04-25 11:16:16.3715037 +0200 CEST", "token_elevation_type": "DEFAULT", "token_integrity_level": "SYSTEM", "token_is_elevated": true, "username": "SYSTEM" }, "callstack": [ "fffff8068ebe0c94 unbacked!", "fffff8068ea589af unbacked!", "fffff8068eb991c2 unbacked!", "fffff8068f1458ee unbacked!", "fffff8068f145624 unbacked!", "fffff8068f0a0a21 unbacked!", "fffff8068f2c956e unbacked!", "fffff8068eebd955 unbacked!", "7ffa53823514 C:\\Windows\\System32\\ntdll.dll!ZwCreateUserProcess", "7ffa537bd0ad C:\\Windows\\System32\\ntdll.dll!RtlNormalizeProcessParams", "7ffa537bcc54 C:\\Windows\\System32\\ntdll.dll!RtlCreateUserProcessEx", "7ff7e09c325d C:\\Windows\\System32\\smss.exe!?", "7ff7e09c2e6c C:\\Windows\\System32\\smss.exe!?", "7ff7e09c29f5 C:\\Windows\\System32\\smss.exe!?", "7ff7e09c194a C:\\Windows\\System32\\smss.exe!?", "7ff7e09c1316 C:\\Windows\\System32\\smss.exe!?", "7ff7e09c11a6 C:\\Windows\\System32\\smss.exe!?", "7ffa5374c412 C:\\Windows\\System32\\ntdll.dll!RtlUserThreadStart" ], "proc": { "pid": 7032, "tid": 3480, "ppid": 4936, "name": "csrss.exe", "exe": "C:\\WINDOWS\\system32\\csrss.exe", "cmdline": "%SystemRoot%\\system32\\csrss.exe ObjectDirectory=\\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16", "parent_name": "smss.exe", "parent_cmdline": "\\SystemRoot\\System32\\smss.exe 00000124 000000b8 winlogon.exe {F481D527-E8FA-457D-87F9-084B51C10000}", "sid": "S-1-5-18", "username": "SYSTEM", "domain": "NT AUTHORITY", "session_id": 3, "integrity_level": "SYSTEM", "is_wow64": false, "is_packaged": false, "is_protected": true, "ancestors": [ "smss.exe (4936)", "smss.exe (440)", "System (4)", "Idle (0)", "Idle (0)" ] } } ] }{ "id": "4ab688f7-94e2-481b-9c7f-c49f3a79a379", "title": "Suspicious access to Windows Credential Manager files", "severity": "low", "description": "Identifies suspicious processes trying to acquire credentials from the Windows Credential Manager.\n", "labels": { "subtechnique.id": "T1555.004", "subtechnique.name": "Windows Credential Manager", "subtechnique.ref": "https://attack.mitre.org/techniques/T1555/004/", "tactic.id": "TA0006", "tactic.name": "Credential Access", "tactic.ref": "https://attack.mitre.org/tactics/TA0006/", "technique.id": "T1555", "technique.name": "Credentials from Password Stores", "technique.ref": "https://attack.mitre.org/techniques/T1555/" }, "events": [ { "name": "CreateFile", "category": "file", "timestamp": "2026-04-25T11:09:46.5522279+02:00", "params": { "attributes": "", "create_disposition": "OPEN", "create_options": "SYNCHRONOUS_IO_NONALERT", "file_object": "ffffb20eb8391c10", "file_path": "C:\\Users\\rededr\\AppData\\Local\\Microsoft\\Credentials\\DFBE70A7E5CC19A398EBF1B96859CE5D", "irp": "ffffb20ebb361428", "share_mask": "READ|WRITE|DELETE", "status": "Success", "tid": 9208, "type": "Directory" }, "callstack": [ "fffff8068ebe0c94 unbacked!", "fffff8068ea589af unbacked!", "fffff8068eb22f86 unbacked!", "fffff80621c06d24 unbacked!", "fffff8062048baaf unbacked!", "fffff8062048b1a0 unbacked!", "fffff806204f68e0 unbacked!", "fffff8068eba953b unbacked!", "fffff8068eba94b3 unbacked!", "fffff8068f09a83b unbacked!", "fffff8068f098812 unbacked!", "fffff8068f0965e3 unbacked!", "fffff8068f1664bf unbacked!", "fffff8068f165699 unbacked!", "fffff8068eebd955 unbacked!", "7ffa538225a4 C:\\Windows\\System32\\ntdll.dll!ZwCreateFile", "7ffa50de5537 C:\\Windows\\System32\\KernelBase.dll!GetDriveTypeW", "7ffa50de6e27 C:\\Windows\\System32\\KernelBase.dll!CreateFileW", "7ffa47f7a623 C:\\Windows\\System32\\sysmain.dll!?", "7ffa47f7877e C:\\Windows\\System32\\sysmain.dll!?", "7ffa47f781e7 C:\\Windows\\System32\\sysmain.dll!?", "7ffa47f738d0 C:\\Windows\\System32\\sysmain.dll!?", "7ffa47f7474c C:\\Windows\\System32\\sysmain.dll!?", "7ffa47f74fe1 C:\\Windows\\System32\\sysmain.dll!?", "7ffa47fddcb5 C:\\Windows\\System32\\sysmain.dll!PfSvUnattendCallback", "7ffa5269e8d7 C:\\Windows\\System32\\kernel32.dll!BaseThreadInitThunk", "7ffa5374c3fc C:\\Windows\\System32\\ntdll.dll!RtlUserThreadStart" ], "proc": { "pid": 1044, "tid": 9208, "ppid": 824, "name": "svchost.exe", "exe": "C:\\WINDOWS\\system32\\svchost.exe", "cmdline": "C:\\WINDOWS\\system32\\svchost.exe -k LocalSystemNetworkRestricted -p -s SysMain", "parent_name": "services.exe", "parent_cmdline": "C:\\WINDOWS\\system32\\services.exe", "cwd": "C:\\WINDOWS\\system32\\", "sid": "S-1-5-18", "username": "SYSTEM", "domain": "NT AUTHORITY", "session_id": 0, "integrity_level": "", "is_wow64": false, "is_packaged": false, "is_protected": false, "ancestors": [ "services.exe (824)", "wininit.exe (680)" ] } } ] }Thanks for posting those. We'll reduce the noise
Metadata
Metadata
Assignees
Labels
No labels
Issue
Operating Fibratus in a clean system, like a freshly installed windows (with commonly installed apps), generates alerts.
Expectation
Operating under a non-infected system should not generate any alerts, as it is not compromised or under attack.
Proposal
Test all the rules regularly against standard non-infected systems, and sensibly whitelist false positives.
This should include:
Additional context
Some of alerts i get in the log file attached to #567 by just idling the VM: