1. Subhabrata Das
  2. PowerBuilder
  3. Monday, 12 February 2024 15:49 PM UTC

Hello Appeon Community Members,

 

Post migration from PowerBuilder version 2017 (v2017 R3 Build 1880) to PowerBuilder 2022 (v2022 Build 1900), two of the executables are getting quarantined by CrowdStrike. There is no code change for these applications. Only these have been migrated from one PowerBuilder version to another.

 

Compared the size of the executables for the two different PB versions and noticed difference in the file size as follows.

 

e.g., executable which was built using PB2017 is of size 52kb, whereas the same application which was built using PB2022 is of size 202kb.

 

Please note that, this issue is not happening for all the executables. Only two executables are getting affected.

 

Did anyone face similar kind of issue after migration?

 

Is there any way to get detail information what might have changed due to the PB version migration?

 

Please suggest any solution. Let me know if any other information is required.

 

 

Francisco Martinez @Appeon Accepted Answer Pending Moderation
  1. Monday, 12 February 2024 16:09 PM UTC
  2. PowerBuilder
  3. # 1

Are the applications signed?

One of the most often suggested solutions for these kind of false positives is signing the binaries.

 

Regards,
Francisco

Comment
  1. mike S
  2. Monday, 12 February 2024 16:21 PM UTC
signing is the solution. no real way around it (except for going to every machine and setting up exclusions in the AV )



code signing is a lot more painful these days since the new hardware token requirements went into place last year.
  1. Helpful
There are no comments made yet.
  • Page :
  • 1


There are no replies made for this question yet.
However, you are not allowed to reply to this question.