Problem when install Workforce AI Security Agent w... - Check Point CheckMates

Problem when install Workforce AI Security Agent with third-party EDR

We're testing a client's Workforce AI Security solution. In the stations, there is an EDR that uses Trend Micro, and when we try to install the agent on several stations (not all), a message appears from this EDR indicating an alert for a detection.

I think is a kind of false positive detection, however I don´t have an official evidence or response about the .exe file to demonstrate the case. Can anybody help me to determine in the best way or provide some information to support the valid use of the executable for GenAI Protection and relieve the concern about the program? Because we try to introduce the solution and the client does not have experience in Check Point products, and when the alert appears trigger his suspicion.

The alert appears over mcp-protect-windows-remote-x86_64.exe, and the name of detection (in TrendMicro) indicates Troj.Win32.TRX.XXPE50F13034. I attached a screenshot.

Responses

PhoneBoy

From looking at the screenshot, it seems like an accurate description of what our Workforce AI Security Agent does. The issue would have to be addressed on the Trend Micro end.

L__Miguel_Aucat

Thanks for your reply, but, do you have an official link or document that demonstrates the process that includes references to the executable (mcp-protect-windows-remote-x86_64.exe) or related process to illustrate the points in which it acts in this way? It's difficult to tell a new client: "That's just how it works" without evidence.

PhoneBoy

I'll see if I can get more details from our product experts. However, I would report the issue through Trend Micro.