Root Cause Analysis – DRMM Agent Services Incorrectly Flagged by Endpoint Security Software
Summary
Between 2026-07-30 17:00 UTC and 2026-07-31 18:43 UTC, some Datto RMM customers on the Syrah platform experienced issues following the deployment of agent version 15.1.0. The issue affected endpoints utilizing Sophos, where certain DRMM agent services were identified as malicious. In affected environments, agent files were quarantined or removed, causing the Datto RMM agent to become non-functional until remediation actions were completed.
The issue affected a subset of customers and was resolved after coordination with the security vendor.
Root Cause
Following the deployment of DRMM agent version 15.1.0, certain agent components were incorrectly identified as malicious by a third-party endpoint security vendor. The detection was a false positive and was not the result of malware or unauthorized code within the DRMM agent. Investigation determined that the detection was likely related to changes in the digital signing reputation of the agent files, which caused the security tool to classify legitimate agent activity as suspicious.
Incident Timeline
Identified: 2026-07-30 21:00 UTC
Public Notification: 2026-07-31 02:27 UTC
Resolved: 2026-07-31 18:43 UTC
Preventative Measures
To reduce the likelihood and impact of similar incidents in the future, we are implementing the following improvements:
Enhancements to Release Validation
Further strengthen our pre-release validation by incorporating a broader set of security and threat-intelligence platforms before agent updates are broadly deployed.
Broaden third-party endpoint security testing to further improve early detection of potential false-positive classifications before release.
Enhancements to Vendor Coordination
Expand the existing file reputation submission process to include additional security providers to further improve coordination and response options, reducing reliance on a single vendor path.
Establish more formalized engagement processes with security vendors to facilitate faster review and resolution of false-positive detections.
Enhancements to Agent Deployment Practices
Evaluate staged agent rollout capabilities that would allow updates to be gradually deployed to a subset of endpoints before broader distribution limiting the scope of impact when issues are detected.
Use phased deployments to identify unexpected environmental interactions earlier and further reduce potential customer impact.
Enhancements to Agent Update Architecture
Review and improve elements of the agent update mechanism to reduce the likelihood that normal update activities are misinterpreted by security software.
Continue refining update workflows to improve compatibility with modern endpoint protection technologies to further reduce the risk of false positive classifications