Troubleshoot Indicator of Attack Detections

Applies To: WatchGuard Advanced EPDR, WatchGuard EPDR, WatchGuard EDR, WatchGuard EPP

WatchGuard Threat Hunting Services help detect Indicators of Attack (IOA). IOAs are confirmed events that are highly likely to be attacks; however, false positives can occur.

For more information about IOAs and how to manage them, go to:

If you want to report a specific IOA detection as a false positive, before you contact WatchGuard Support, complete these steps to collect information for your Support case:

  • Provide a description of the issue.
  • Use the PSInfo tool to gather support-related information.
  • Enable Support Access to your WatchGuard Cloud account.