An integrated threat protection solution designed to detect, investigate, and respond to cyber threats across Microsoft 365 services.
Confirmation of a specific detection as a false positive cannot be provided.
To handle this case:
- Identify the detection source
- In Microsoft Defender for Endpoint / Defender XDR, open the alert and check the alert source and detection source (for example, Antivirus, EDR, Custom TI, PUA protection, etc.).
- Use the guidance in the "Identify the detection source" section to determine whether this came from Microsoft Defender Antivirus, EDR, custom indicators, or other components.
- Submit the file or detection as a possible false positive
- For files or apps on a device that are suspected to be wrongly detected, submit the file to Microsoft for malware analysis using the Microsoft Security Intelligence submission site as described in Submit a file to Microsoft for malware analysis.
- For Defender for Endpoint detections, use the guidance in Address false positives/negatives in Microsoft Defender for Endpoint and submit the false positive to the portal at
https://aka.ms/wdsi.
- (Optional) Apply a temporary workaround if business‑critical
- If the detection is blocking legitimate Postman usage and operations are impacted, use one of the documented workarounds while waiting for Microsoft’s verdict:
- Create an Indicator – File hash – allow for the specific, verified‑safe file.
- Or configure an appropriate Antivirus exclusion or EDR exclusion, or tune the alert, depending on the detection source.
- These workarounds should be scoped as narrowly as possible and only applied after verifying the file’s legitimacy, because exclusions reduce protection.
- If the detection is blocking legitimate Postman usage and operations are impacted, use one of the documented workarounds while waiting for Microsoft’s verdict:
- If this is part of a penetration test or controlled simulation
- Follow the “How to submit possible false negatives for investigation” / diagnostic guidance when gathering logs and details (OrgID, DeviceID, binaries, timestamps, reproduction steps) so Microsoft can accurately assess whether the detection is correct or a false positive.
- Monitor for additional indicators
- Continue reviewing Defender alerts, Advanced Hunting results, and Entra sign‑in/audit logs for any unusual activity, but rely on Microsoft’s submission response to determine whether the specific
Trojan:Script/Stealer.HBF!MTBdetection on Postman is ultimately classified as a false positive.
- Continue reviewing Defender alerts, Advanced Hunting results, and Entra sign‑in/audit logs for any unusual activity, but rely on Microsoft’s submission response to determine whether the specific
References: