> Source: [sk181212](https://support.checkpoint.com/results/sk/sk181212)

# sk181212 - Threat Emulation blade of the Windows Endpoint Security Client quarantines ConnectWise / Anyconnect application

| Property | Value |
|----------|-------|
| Solution ID | sk181212 |
| Date Created | 2023-07-04 |
| Last Modified | 2024-05-14 |
| Technical Level | Advanced |
| Products | Security Gateway, Endpoint Security |
| Versions | R82.10, R82, R81.20, Cloud, E89.X, E88.X, R82.20, R82.10, R82, R81.20 |
| OS | Windows |

## Symptoms

- * The Threat Emulation blade of the Endpoint Security Client for Windows quarantines the ConnectWise application.
* The signer name of the quarantined ConnectWise application is "Connectwise, LLC" - with lower case "w".

## Cause

The Threat Emulation blade identifies ConnectWise as a Potentially Unwanted Application (PUA), as it can be used by Threat Actors. Therefore Static Analysis identifies the application as malicious. There is no option to exclude a PUA process from Static Analysis.  

The Threat Emulation blade has a default exclusion for ConnectWise's specific signer file. Because ConnectWise changes the name of the file signer, or doesn't sign the installer at all, Threat Emulation does not apply the default exclusion.  

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
