False Positive 2065016 ET TROJAN BPFDoor Heartbeat (Outbound)

This rule triggered 2025/10/02 - 2025/10/03 on (Amazon) Ring Doorbell and Ring Floodlight devices. I spoke with Ring Customer Service who said the devices were performing a legitimate firmware update.

2065016 - ET TROJAN BPFDoor Heartbeat (Outbound)

1 Like

Same here, this rule killed our phone connectivity by blocking the SIP host of our phone provider. :roll_eyes:

1 Like

Hey @FastForward2025 @jacotec - Apologies for the issues! We just deactivated the rule so if you pull the latest ruleset that should resolve the FP’s.

Let me know if there’s anything else and I’m happy to help!

Thanks,
Isaac

1 Like