duplicate incidents being created for removeable storage on MacOS
search cancel

duplicate incidents being created for removeable storage on MacOS

book

Article ID: 395173

calendar_today

Updated On:

Products

Data Loss Prevention Core Package

Issue/Introduction

We have noticed a steady increase in events related to MacOS endpoints and removable media activity for an application called doubledagent. it appears that this is related to the file storage/system’s format and how MacOS handles extended attributes of files (saving parts of them in two files).

Cause

Multiple detection requests from DoubleAgent.framework in macOS is causing duplicate incidents

Resolution

Work around:  add doubleagentD to application monitoring and whitelist.

Code correction in 25.1 will address several issues introduced by doubleagentD