> Source: [sk184295](https://support.checkpoint.com/results/sk/sk184295)

# sk184295 - Microsoft Defender for Cloud identifies the sigs_package.tar.gz on a Check Point Security Gateway as malicious

| Property | Value |
|----------|-------|
| Solution ID | sk184295 |
| Date Created | 2025-12-15 |
| Last Modified | 2025-12-17 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- A Check Point Security Gateway is hosted in Azure. Microsoft Defender for Cloud identifies the *sigs_package.tar.gz* file on the Security Gateway as malicious.

## Cause

Microsoft Defender incorrectly reports the *sigs_package.tar.gz* file as malicious. This is a false positive.  
The *sigs_package.tar.gz* file is a legitimate Check Point signature package that the Security Gateway downloads as part of regular Threat Prevention updates (for example: IPS, Anti-Virus, Anti-Bot). The Gateway downloads the file from official Check Point servers.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
