[GH-ISSUE #5752] ESET Antivirus is now reporting Netbird as a PUA #11713

Open
opened 2026-08-05 01:30:39 -04:00 by saavagebueno · 23 comments
Owner

Originally created by @Br0kenSilos on GitHub (Mar 31, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5752

As of this morning this morning, ESET Anti-Virus has started flagging Netbird as a PUA (Potentially Unwanted Application) and removing and blocking Netbird from Windows computers as well as deleting the installers. This is happening at least the most recent two versions of Netbird for Windows. "netbird_installer_0.67.1_windows_amd64.exe" and "netbird_installer_0.66.4_windows_amd64.exe"

This is obviously a false positive but at least in my case, its eating the executables and disconnecting machines. I have reported this to ESET as well but wanted to make you aware as it could be catastrophic for larger entities using Netbird.

Originally created by @Br0kenSilos on GitHub (Mar 31, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/5752 As of this morning this morning, ESET Anti-Virus has started flagging Netbird as a PUA (Potentially Unwanted Application) and removing and blocking Netbird from Windows computers as well as deleting the installers. This is happening **at least** the most recent two versions of Netbird for Windows. "netbird_installer_0.67.1_windows_amd64.exe" and "netbird_installer_0.66.4_windows_amd64.exe" This is obviously a false positive but at least in my case, its eating the executables and disconnecting machines. I have reported this to ESET as well but wanted to make you aware as it could be catastrophic for larger entities using Netbird.
Author
Owner

@alfrede commented on GitHub (Apr 1, 2026):

I have the same Problem with a Version 0.67.0_windows_amd64.exe and older.
Eset with the following Versions: ESET Endpoint Antivirus: 12.1.2057.3 and the following Modules:

Detection Engine;32936;01. Apr. 2026
Rapid Response module;28047;01. Apr. 2026
Update module;1043;08. Jul. 2025
Antivirus and antispyware scanner module;1635;24. Mrz. 2026
Advanced heuristics module;1234.3;23. Mrz. 2026
Archive support module;1361;19. Feb. 2026
Cleaner module;1262;05. Feb. 2026
Anti-Stealth support module;1202;20. Jan. 2026
Firewall module;1462;23. Feb. 2026
Translation support module;2079;23. Mrz. 2026
HIPS support module;1518.3;30. Mrz. 2026
Internet protection module;1510;29. Jan. 2026
Database module;1134;26. Jan. 2026
Configuration module;2224.3;09. Mrz. 2026
Direct Cloud communication module;1152;13. Jan. 2026
Secure Browser module;1411;17. Feb. 2026
Rootkit detection and cleaning module;1034;06. Nov. 2024
Network protection module;1701;30. Jul. 2025
Network Inspector module;1048;20. Jan. 2022
Cryptographic protocol support module;1095;25. Feb. 2026
Deep behavioral inspection support module;1236;04. Mrz. 2026
Advanced Machine Learning module;1218;04. Mrz. 2026
Telemetry module;1067;06. Nov. 2024
Security Center integration module;1041;24. Jun. 2024

<!-- gh-comment-id:4169882728 --> @alfrede commented on GitHub (Apr 1, 2026): I have the same Problem with a Version 0.67.0_windows_amd64.exe and older. Eset with the following Versions: ESET Endpoint Antivirus: 12.1.2057.3 and the following Modules: Detection Engine;32936;01. Apr. 2026 Rapid Response module;28047;01. Apr. 2026 Update module;1043;08. Jul. 2025 Antivirus and antispyware scanner module;1635;24. Mrz. 2026 Advanced heuristics module;1234.3;23. Mrz. 2026 Archive support module;1361;19. Feb. 2026 Cleaner module;1262;05. Feb. 2026 Anti-Stealth support module;1202;20. Jan. 2026 Firewall module;1462;23. Feb. 2026 Translation support module;2079;23. Mrz. 2026 HIPS support module;1518.3;30. Mrz. 2026 Internet protection module;1510;29. Jan. 2026 Database module;1134;26. Jan. 2026 Configuration module;2224.3;09. Mrz. 2026 Direct Cloud communication module;1152;13. Jan. 2026 Secure Browser module;1411;17. Feb. 2026 Rootkit detection and cleaning module;1034;06. Nov. 2024 Network protection module;1701;30. Jul. 2025 Network Inspector module;1048;20. Jan. 2022 Cryptographic protocol support module;1095;25. Feb. 2026 Deep behavioral inspection support module;1236;04. Mrz. 2026 Advanced Machine Learning module;1218;04. Mrz. 2026 Telemetry module;1067;06. Nov. 2024 Security Center integration module;1041;24. Jun. 2024
Author
Owner

@MD7070B commented on GitHub (Apr 2, 2026):

Also ran into this on my machine with ESET Endpoint - I created a local exclusion for netbird.exe and reported as a false positive to ESET. Their response was:

The classification is correct. Typical solution for intentionally installed PUAs is to create local detection exclusion.

Seems their logic is that Netbird is not definitely malicious - rather, it could be potentially unwanted / unsafe...

<!-- gh-comment-id:4177898066 --> @MD7070B commented on GitHub (Apr 2, 2026): Also ran into this on my machine with ESET Endpoint - I created a local exclusion for `netbird.exe` and reported as a false positive to ESET. Their response was: > The classification is correct. Typical solution for intentionally installed PUAs is to create local detection exclusion. Seems their logic is that Netbird is not *definitely malicious* - rather, it *could be* potentially unwanted / unsafe...
Author
Owner

@Br0kenSilos commented on GitHub (Apr 2, 2026):

Same response I got. ESET is starting to report anything that "could" be used by a malicious actor as a PUA these days. They have also marked our RMM this way. Problem is, when they just arbitrarily decide to remove legit programs without any warning what so ever and those programs are used for things like VPN or RMM, they cause people to have to go through a lot of manual leg work to fix it. What they really should do, is not just automatically remove said programs, but instead they should pop notifications to the users to say they think a program is a PUA and give the user the opportunity to decide or to reach out to their IT department if they have one.

To be clear this is not a Netbird problem. Its a problem with ESET's philosophy on how they handle these things. I love that AV and feel like its the most effective on the market.. But this is strike #2 for them with me. If they hit strike #3 and cause me to go through a bunch of work running around and fixing machines with another critical software, I will have to dump them.

<!-- gh-comment-id:4178398159 --> @Br0kenSilos commented on GitHub (Apr 2, 2026): Same response I got. ESET is starting to report anything that "could" be used by a malicious actor as a PUA these days. They have also marked our RMM this way. Problem is, when they just arbitrarily decide to remove legit programs without any warning what so ever and those programs are used for things like VPN or RMM, they cause people to have to go through a lot of manual leg work to fix it. What they really should do, is not just automatically remove said programs, but instead they should pop notifications to the users to say they think a program is a PUA and give the user the opportunity to decide or to reach out to their IT department if they have one. To be clear this is not a Netbird problem. Its a problem with ESET's philosophy on how they handle these things. I love that AV and feel like its the most effective on the market.. But this is strike #2 for them with me. If they hit strike #3 and cause me to go through a bunch of work running around and fixing machines with another critical software, I will have to dump them.
Author
Owner

@Br0kenSilos commented on GitHub (Apr 2, 2026):

Here is their response to me:

"Thank you for your submission.The classification is correct. https://help.eset.com/glossary/en-US/unsafe_application.html"

Potentially unsafe applications
ESET Online Help > ESET Glossary > Detections > Potentially unsafe applications

There are many legitimate programs whose function is to simplify the administration of networked computers. However, they may be misused for malicious purposes in the wrong hands. ESET provides the option to detect such applications.

Potentially unsafe applications is the classification used for commercial, legitimate software. This classification includes programs such as remote access tools, password-cracking applications, and keyloggers (a program that records each keystroke a user types).

If you find a potentially unsafe application running on your computer (and you did not install it), please consult your network administrator or remove it.

At its core, Netbird is primarily a VPN. It is not "It is not a remote access tool, password cracking application, or a keylogger" Hopefully the folks at Netbird can convince ESET that its not a PUA.

Personally I've about had it with ESET and their hard nosed shenanigans regarding PUAs. Their attitude basically screams not to use their product if you are a business.

<!-- gh-comment-id:4179345246 --> @Br0kenSilos commented on GitHub (Apr 2, 2026): Here is their response to me: "Thank you for your submission.The classification is correct. https://help.eset.com/glossary/en-US/unsafe_application.html" The page that link points to states: ------ Potentially unsafe applications [ESET Online Help](https://help.eset.com/?lang=en-US&segment=home) > [ESET Glossary](https://help.eset.com/glossary/en-US/) > Detections > Potentially unsafe applications There are many legitimate programs whose function is to simplify the administration of networked computers. However, they may be misused for malicious purposes in the wrong hands. ESET provides the option to detect such applications. Potentially unsafe applications is the classification used for commercial, legitimate software. This classification includes programs such as remote access tools, password-cracking applications, and keyloggers (a program that records each keystroke a user types). If you find a potentially unsafe application running on your computer (and you did not install it), please consult your network administrator or remove it. ----- At its core, Netbird is primarily a VPN. It is not "It is not a remote access tool, password cracking application, or a keylogger" Hopefully the folks at Netbird can convince ESET that its not a PUA. Personally I've about had it with ESET and their hard nosed shenanigans regarding PUAs. Their attitude basically screams not to use their product if you are a business.
Author
Owner

@MD7070B commented on GitHub (Apr 2, 2026):

Good points. I personally haven't yet had an instance in a business environment where a software already in use is suddenly flagged and removed - maybe it will come. Closest I've come is installing new piece of software on my workstation (like Netbird in this example), running into the PUA thing, and having to create a local exception (after double checking the application is OK).

<!-- gh-comment-id:4179630070 --> @MD7070B commented on GitHub (Apr 2, 2026): Good points. I personally haven't yet had an instance in a business environment where a software already in use is suddenly flagged and removed - maybe it will come. Closest I've come is installing new piece of software on my workstation (like Netbird in this example), running into the PUA thing, and having to create a local exception (after double checking the application is OK).
Author
Owner

@Br0kenSilos commented on GitHub (Apr 2, 2026):

Agreed. If it flags only during install, that would be different because you could then go ahead and make the exception and try to install again. In my case, it not only ate the installer that I had (because I always keep the two most recent installers in a folder). But it also ate the active netbird client. Killed the connection, netbird.exe gone. And thats just not ok for them to do for a "PUA". If it were well defined malware or a known virus, that would be a different story.

<!-- gh-comment-id:4179924823 --> @Br0kenSilos commented on GitHub (Apr 2, 2026): Agreed. If it flags only during install, that would be different because you could then go ahead and make the exception and try to install again. In my case, it not only ate the installer that I had (because I always keep the two most recent installers in a folder). But it also ate the active netbird client. Killed the connection, netbird.exe gone. And thats just not ok for them to do for a "PUA". If it were well defined malware or a known virus, that would be a different story.
Author
Owner

@Dianadick commented on GitHub (Apr 9, 2026):

We just had ESET flag and remove our NetBird agent and just a week prior, it deleted Datto RMM across hundreds of client machines, causing a major outage.
This shouldn't be happening. ESET is one of the best AV products on the market, yet it's classifying legitimate, widely used management and remote access tools as PUAs. As an MSP, we can't be expected to preemptively create exclusions for every tool in our stack just to prevent ESET from taking them down.
An AV solution should not be the cause of outages...

<!-- gh-comment-id:4213670190 --> @Dianadick commented on GitHub (Apr 9, 2026): We just had ESET flag and remove our NetBird agent and just a week prior, it deleted Datto RMM across hundreds of client machines, causing a major outage. This shouldn't be happening. ESET is one of the best AV products on the market, yet it's classifying legitimate, widely used management and remote access tools as PUAs. As an MSP, we can't be expected to preemptively create exclusions for every tool in our stack just to prevent ESET from taking them down. An AV solution should not be the cause of outages...
Author
Owner

@Br0kenSilos commented on GitHub (Apr 9, 2026):

I agree. We are re-evaluating the use of ESET at this point because they are just too aggressive with PUA's and they refuse to back off on blocking LEGIT programs. And IMO, disabling PUA detection is the wrong way to handle it too. We love the detection of PUA's but, this thing os just automatically removing them without notification or warning has got to stop. Really all they need to do is to change the detection behavior so that the user is alerted, and give the chance to decide what to do (whitelist, quarantine, remove, etc) BEFORE any action is actually taken. But the people at ESET just aren't listening it seems.

<!-- gh-comment-id:4215353713 --> @Br0kenSilos commented on GitHub (Apr 9, 2026): I agree. We are re-evaluating the use of ESET at this point because they are just too aggressive with PUA's and they refuse to back off on blocking LEGIT programs. And IMO, disabling PUA detection is the wrong way to handle it too. We love the detection of PUA's but, this thing os just automatically removing them without notification or warning has got to stop. Really all they need to do is to change the detection behavior so that the user is alerted, and give the chance to decide what to do (whitelist, quarantine, remove, etc) BEFORE any action is actually taken. But the people at ESET just aren't listening it seems.
Author
Owner
<!-- gh-comment-id:4238170601 --> @alfrede commented on GitHub (Apr 13, 2026): You can try this Article https://support.eset.com/de/kb8115-create-an-exclusion-for-a-potentially-unwanted-application-in-eset-protect
Author
Owner

@Br0kenSilos commented on GitHub (Apr 13, 2026):

Agreed. We "can" create an exclusion and that works. I have not done it on all the systems I am able to reach. The problem is more systemic with ESET. They will suddenly, arbitrarily, decide a program is a PUA, and just remove it without warning. Having to preemptively white list every program you use on computers that also run ESET (Not console managed mind you) is crazy. Because you never know what ESET will just suddenly decide is a PUA.

This is NOT a netbird issue. It's an ESET issue for sure. But when people runnign netbird suddenly lose connections and want to know why... Here it is. I tried reaching out to ESET, twice.. They just don't care as they have decided that netbird is malicious and there is nothing we can do to change their minds.

Its pretty infuriating TBH and I am planning to drop ESET and have all my friends, family, and clients drop them as well during next renewal period because of their stance on how they deal with PUA's. - What they need to is really simple.. Instead of just removing programs without warning or permission, they should be popping a message to the user so the user can decide. PUA's does not equal malware or virus.

<!-- gh-comment-id:4238909906 --> @Br0kenSilos commented on GitHub (Apr 13, 2026): Agreed. We "can" create an exclusion and that works. I have not done it on all the systems I am able to reach. The problem is more systemic with ESET. They will suddenly, arbitrarily, decide a program is a PUA, and just remove it without warning. Having to preemptively white list every program you use on computers that also run ESET (Not console managed mind you) is crazy. Because you never know what ESET will just suddenly decide is a PUA. This is NOT a netbird issue. It's an ESET issue for sure. But when people runnign netbird suddenly lose connections and want to know why... Here it is. I tried reaching out to ESET, twice.. They just don't care as they have decided that netbird is malicious and there is nothing we can do to change their minds. Its pretty infuriating TBH and I am planning to drop ESET and have all my friends, family, and clients drop them as well during next renewal period because of their stance on how they deal with PUA's. - What they need to is really simple.. Instead of just removing programs without warning or permission, they should be popping a message to the user so the user can decide. PUA's does not equal malware or virus.
Author
Owner

@MD7070B commented on GitHub (Apr 14, 2026):

I did just notice this option in ESET PROTECT when downloading an installer to use on a new machine:

Image

I haven't tried toggling it off (not running Netbird on these machines anyway), but not sure if this might help?

<!-- gh-comment-id:4241804006 --> @MD7070B commented on GitHub (Apr 14, 2026): I did just notice this option in ESET PROTECT when downloading an installer to use on a new machine: <img width="908" height="543" alt="Image" src="https://github.com/user-attachments/assets/5692d088-a38f-45cb-adcd-49d8b7743ffa" /> I haven't tried toggling it off (not running Netbird on these machines anyway), but not sure if this might help?
Author
Owner

@Br0kenSilos commented on GitHub (Apr 14, 2026):

Agreed. Yep, we can do that too. And maybe thats what we will have to do until either ESET comes to it's senses, or we switch to a different AV. But, I would prefer being able to leave it on. It just needs to ask user permission to disable an app. It would be different if the app was for sure a virus or malware. In that case you want ti to respond immediately. But for a Potentially Unwanted Program, it shoudl ask the user what to do. Just my two cents.

<!-- gh-comment-id:4243866325 --> @Br0kenSilos commented on GitHub (Apr 14, 2026): Agreed. Yep, we can do that too. And maybe thats what we will have to do until either ESET comes to it's senses, or we switch to a different AV. But, I would prefer being able to leave it on. It just needs to ask user permission to disable an app. It would be different if the app was for sure a virus or malware. In that case you want ti to respond immediately. But for a Potentially Unwanted Program, it shoudl ask the user what to do. Just my two cents.
Author
Owner

@MD7070B commented on GitHub (Apr 14, 2026):

Yes.

It just needs to ask user permission to disable an app.

Or ask an Admin what to do, via the portal?

Are you running ESET PROTECT, or the standalone Endpoint versions?

<!-- gh-comment-id:4244063345 --> @MD7070B commented on GitHub (Apr 14, 2026): Yes. > It just needs to ask user permission to disable an app. Or ask an Admin what to do, via the portal? Are you running ESET PROTECT, or the standalone Endpoint versions?
Author
Owner

@Br0kenSilos commented on GitHub (Apr 14, 2026):

It's a mixed bag. At work we run ESET PROTECT and can control it centrally. That's easy enough. Friends, family, and clients on the other hand... Those are ALL standalone endpoints. And some are not local and 90% are totally computer illiterate, which complicates matters.

<!-- gh-comment-id:4244286281 --> @Br0kenSilos commented on GitHub (Apr 14, 2026): It's a mixed bag. At work we run ESET PROTECT and can control it centrally. That's easy enough. Friends, family, and clients on the other hand... Those are ALL standalone endpoints. And some are not local and 90% are totally computer illiterate, which complicates matters.
Author
Owner

@jpardo90 commented on GitHub (Apr 16, 2026):

Hi team

Recently (Today) on my company our antimalware Solution (Trellix Endpoint solution ENS) have start detect the netbird proccess "netbird-ui.exe" as a suspicius Process

Let here detaill info about this detection

Image Image
<!-- gh-comment-id:4263728012 --> @jpardo90 commented on GitHub (Apr 16, 2026): Hi team Recently (Today) on my company our antimalware Solution (Trellix Endpoint solution ENS) have start detect the netbird proccess "netbird-ui.exe" as a suspicius Process Let here detaill info about this detection <img width="1896" height="672" alt="Image" src="https://github.com/user-attachments/assets/36bef922-cbc0-45d8-b79b-922ee23a7dcc" /> <img width="949" height="308" alt="Image" src="https://github.com/user-attachments/assets/92b35c7c-f534-426f-b4c6-e1f6cd18e404" />
Author
Owner

@Arouraios commented on GitHub (Apr 27, 2026):

Same issue here. Downloading and installing the latest netbird version usually fixes it for a day or two, but after that netbird-ui.exe gets purged again. Adding an exception for netbird-ui.exe in Trellix leads to Trellix blocking powershell.exe and rundll32.exe.

<!-- gh-comment-id:4324449711 --> @Arouraios commented on GitHub (Apr 27, 2026): Same issue here. Downloading and installing the latest netbird version usually fixes it for a day or two, but after that netbird-ui.exe gets purged again. Adding an exception for netbird-ui.exe in Trellix leads to Trellix blocking powershell.exe and rundll32.exe.
Author
Owner

@Arouraios commented on GitHub (May 4, 2026):

I was hopeful the new signatures might change something, but I have just installed v0.70.4 and the issue persists.
This is a showstopper for our planned migration to Netbird. We will also contact Trellix Support and I will update if we can solve the issue without manually whitelisting every executable involved.

<!-- gh-comment-id:4368926948 --> @Arouraios commented on GitHub (May 4, 2026): I was hopeful the new signatures might change something, but I have just installed v0.70.4 and the issue persists. This is a showstopper for our planned migration to Netbird. We will also contact Trellix Support and I will update if we can solve the issue without manually whitelisting every executable involved.
Author
Owner

@MD7070B commented on GitHub (May 4, 2026):

I had Netbird running fine on my system, I think I had created an ESET exception. I have yet to investigate, but I woke up the machine just now, and this suddenly occured:

Image

Not aware of having initiated a Netbird update or anything. Pretty random.

<!-- gh-comment-id:4369604060 --> @MD7070B commented on GitHub (May 4, 2026): I had Netbird running fine on my system, I think I had created an ESET exception. I have yet to investigate, but I woke up the machine just now, and this suddenly occured: <img width="1000" height="470" alt="Image" src="https://github.com/user-attachments/assets/1ccc4bc5-c679-492e-a9b2-90cc967283be" /> Not aware of having initiated a Netbird update or anything. Pretty random.
Author
Owner

@jpardo90 commented on GitHub (May 6, 2026):

We were be update to the version 0.69.0 two week ago, and the issue has been disappeared. Tomorrow we will update to 0.70.5.
I let know you any notice!

<!-- gh-comment-id:4393081410 --> @jpardo90 commented on GitHub (May 6, 2026): We were be update to the version 0.69.0 two week ago, and the issue has been disappeared. Tomorrow we will update to 0.70.5. I let know you any notice!
Author
Owner

@KOEWADO commented on GitHub (May 15, 2026):

Something new about this issue?
Running 0.67.1 without problems. But if i try to install >= 0.70x i run into this issue.

<!-- gh-comment-id:4457066898 --> @KOEWADO commented on GitHub (May 15, 2026): Something new about this issue? Running 0.67.1 without problems. But if i try to install >= 0.70x i run into this issue.
Author
Owner

@mlsmaycon commented on GitHub (May 15, 2026):

Hey Folks, the report is a false positive caused by a recent change to the signing certificate we made from version 0.70. The certificate change was necessary because the previous one recently expired.

ESET is ignoring our requests to check this directly via our support inquiries. We also applied to their whitelisting program a few years ago and apply again every year, but we have not yet received a response.

One thing you all can do to help us is submit our installers and binaries as a false positive for them to analyze. In our experience, the more submissions, the better the chance of getting their attention.

<!-- gh-comment-id:4458368483 --> @mlsmaycon commented on GitHub (May 15, 2026): Hey Folks, the report is a false positive caused by a recent change to the signing certificate we made from version 0.70. The certificate change was necessary because the previous one recently expired. ESET is ignoring our requests to check this directly via our support inquiries. We also applied to their whitelisting program a few years ago and apply again every year, but we have not yet received a response. One thing you all can do to help us is submit our installers and binaries as a false positive for them to analyze. In our experience, the more submissions, the better the chance of getting their attention.
Author
Owner

@Arouraios commented on GitHub (Jun 29, 2026):

After an arduous exchange with Trellix support, new Netbird client versions appear to be blocked no longer.

<!-- gh-comment-id:4835855470 --> @Arouraios commented on GitHub (Jun 29, 2026): After an arduous exchange with Trellix support, new Netbird client versions appear to be blocked no longer.
Author
Owner

@arktronic commented on GitHub (Jul 17, 2026):

This issue is also preventing new versions from showing up on WinGet: https://github.com/microsoft/winget-pkgs/pull/402787

<!-- gh-comment-id:5005200564 --> @arktronic commented on GitHub (Jul 17, 2026): This issue is also preventing new versions from showing up on WinGet: https://github.com/microsoft/winget-pkgs/pull/402787
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#11713