Skip to content

docs: Add FAQ entry about EDR vendors flagging the fleetd agent (orbit)#44792

Open
kilo-code-bot[bot] wants to merge 2 commits intomainfrom
docs-faq-edr-fleetd-flagging
Open

docs: Add FAQ entry about EDR vendors flagging the fleetd agent (orbit)#44792
kilo-code-bot[bot] wants to merge 2 commits intomainfrom
docs-faq-edr-fleetd-flagging

Conversation

@kilo-code-bot
Copy link
Copy Markdown
Contributor

@kilo-code-bot kilo-code-bot Bot commented May 5, 2026

Summary

  • Adds a new FAQ entry to docs/Get started/FAQ.md explaining that EDR products (e.g., SentinelOne, CrowdStrike) may occasionally flag the fleetd agent (orbit) after updates
  • Describes the osquery v5.23.0 change that performs temporary keychain file copies to prevent corruption when querying the certificates table, which can trigger EDR heuristic alerts
  • Notes that Fleet is working with EDR vendors to resolve false-positive classifications and advises customers can safely allowlist the orbit binary

Built for Mike McNeil by Kilo for Slack

Add a new FAQ entry explaining that EDR products like SentinelOne and
CrowdStrike may flag the fleetd agent (orbit) after updates due to
heuristic-based detections. Describes the osquery v5.23.0 keychain
access behavior that can trigger alerts, notes that Fleet is working
with vendors to resolve false-positives, and advises customers they
can safely allowlist the orbit binary.
@kilo-code-bot kilo-code-bot Bot requested a review from rachaelshaw as a code owner May 5, 2026 21:11
Copy link
Copy Markdown

@claude claude Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review to trigger a review and subscribe this PR to future pushes, or @claude review once for a one-time review.

Tip: disable this comment in your organization's Code Review settings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant