Ir_agent.exe/token_handler.exe as Mal/Generic-S on Sophos AV

Is anyone else using Sophos seeing detections related to the Rapid7 Insight Agent component token_handler.exe?

We recently saw Sophos flag token_handler.exe under the Rapid7 Insight Agent path:

C:\Program Files\Rapid7\Insight Agent\components\insight_agent\4.11.55\token_handler.exe

Sophos detected it as Mal/Generic-S and later showed the malware as cleaned up. Since this file appears to be part of the Rapid7 Insight Agent installation, I wanted to check whether others are seeing the same alerts and whether this is expected behavior, a known false positive, or something that should be investigated further.

Any confirmation or guidance would be appreciated.

yup, we are talking about here:

Anyone else seeing AV detections against Insight Agent token_handler.exe (v4.1.1.55)? - InsightIDR - Rapid7 Discuss

I just got the same alert.

Niall from Rapid7 is keeping us updated there if you wanna follow the thread :grinning_face: