Posted Saturday at 10:49 PM2 days Several times now, Microsoft Defender for Endpoint has identified the following file as malware and has quaratined it:Filename: pulsewayhardware.sysHashes: Hash SHA1d25340ae8e92a6d29f599fef426a2bc1b5217299Hash SHA25611bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5Threat: Winring0Defender engine version1.1.25050.6Defender Mocamp version4.18.25040.2VirusTotal link:https://www.virustotal.com/gui/file/11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5DetectionVirusTotal detection ratio2/72Malware detectedVulnerableDriver:WinNT/Winring0Object detailsFile size14.54 KBIs PEtrueIssuerGlobalSign ObjectSign CASignerNoriyuki MIYAZAKIPE metadataOriginal nameWinRing0.sysCompanyOpenLibSys.orgProductWinRing0DescriptionWinRing0File prevalenceOrganization devices5Organization cloud apps0Worldwide devices10k+Worldwide observed devicesTimeFirst seenMar 3, 2013 6:00:43 AMLast seenJun 13, 2025 5:47:56 AMIs this an actual Pulseway file and has anyone else experienced this on any of their agents? What other info can I provide?And before anyone asks, I only deploy agents from the SaaS Pulseway server instance.Thanks,Bart B.
11 hours ago11 hr Administrators Hey @BartB - Thanks for reaching out! We are actively addressing this. Our development team is aware of the associated risks, and a dedicated development effort is underway to completely remove and replace the WinRing0 dependency in a future release. This transition is being prioritized to align with modern security best practices, including Microsoft's Vulnerable Driver Blocklist.In the meantime, please be assured Pulseway runs under a service account and does not expose direct user-accessible interfaces to this driver.If you have any other questions, let me know😊
3 hours ago3 hr Author Hello @Mariale_Pulseway , thank you for your reply.What do you recommend I do in the meantime, as Defender keeps detecting the files as malicious and quarantining them? Shoudl I add the "pulsewayhardware.sys" file to eceptions so it stops being flagged? What is the risk asoociated with leaving othe file in place? Does any Pulseway agent functionality break if the file is removed?Thanks!
Create an account or sign in to comment