EDR False Positives for RMM

Incident Report for ISOutsource Internal IT

Resolved

This incident has been resolved.
Posted Jan 02, 2026 - 11:26 PST

Identified

We have active support cases open with Pax8, SentinelOne, and N-able, and are working closely with all parties to reach a resolution as quickly as possible.
Posted Jan 01, 2026 - 19:35 PST

Investigating

We are aware of widespread alerts across multiple EDR platforms related to an N-central file. We have confirmed this to be a false positive through our own analysis of the executable’s behavior as well as independent third-party investigations. Multiple security analysts have reported the same behavior across SentinelOne and Microsoft Defender in public forums.
Posted Jan 01, 2026 - 17:40 PST
This incident affected: BlueVault RMM (BlueVault RMM), SentinelOne EDR (SentinelOne EDR), and PSA - Service Ticket System.