search cancel

Duplicate events appear for EICAR detections

book

Article ID: 162049

calendar_today

Updated On:

Products

Endpoint Detection and Response

Issue/Introduction

Duplicate events appear for EICAR detections.

Resolution

Some browsers (Chrome and Firefox, for example) automatically retry a connection to a website if they encounter a failure. When a browser retries connections, websites that are blocked by the ATP: Network appliance, or by an endpoint security product such as Symantec Endpoint Protection Manager, may show up as 2 convictions that occur simultaneously on the same endpoint. This is because the appliance detects two distinct attempts to go to the blocked site.