SEPM 14. I'm having hundreds of false-positive detections on Heur.AdvML.B across my enterprise. Most of it is in custom code developed and used internally.
I know what Heur.AdvML.B is. I know all about the Machine Learning and Reputation-based detection. I know how to upload files to be whitelisted, and I've done that for several. I know how to exclude individual files, folders, and applications/hashes in the SEPM policy.
I'm looking for the most effective ways to prevent Heur.AdvML.B detections. I'd like instructions on two items -
1) Change the Action for "Heur.AdvML.B" detection to Alert-Only
2) Disable detection for "Heur.AdvML.B" entirely.
In the Exceptions Policy, Known Risks, this doesn't show up as a Known Risk that I can exclude. When right-clicking on one of the detected items in the Monitor-Risks view, Add Exception, when I try to add an exception for the Risk there's a message that this detection cannot be excluded by Risk.
The only thing related that I've found is in teh "Virus and Spyware Protection" Policy, under Global Scan Options, there is an option for "Enable Bloodhound Heuristic virus detection". Will disabling Bloodhound prevent Heur.AdvML.B detections? Is there a more granular way to handle it?
I very much appreciate any help you can give on this.