Has anyone else seen Microsoft Defender detect ScreenConnect.ClientService.exe as Wacatac within the past day? Our managed detection and response provider believes the file is malicious, while ConnectWise support says the alert is a false positive. The Defender timeline looks more consistent with a false detection, but I'd like to compare experiences and understand whether this is related to a recent client update or a genuine compromise.
4 Answers
We see this occasionally across a large fleet, usually during client updates—only one or two systems in a release cycle. If the software is approved and centrally managed, the detection is more likely a false positive, but confirm that the client version is current and obtained from the official source.
Treat it seriously because remote-access tools are frequently abused. A legitimate installation can still be compromised or replaced. Check whether the device is registered to the expected tenant, review recent logins and account activity, and investigate any unexpected installers, persistence, or outbound connections.
There have also been phishing campaigns distributing ScreenConnect installers through compromised business accounts. If the file came from an email, an unapproved download, or a user with administrator rights, assume possible compromise until the machine and access logs are reviewed. Defender deleting the file does not by itself prove the alert was harmless.
Several people are seeing these alerts after ScreenConnect client upgrades. Wacatac and Vigorf detections have appeared intermittently on otherwise normal installations, so this may be a Defender machine-learning false positive. Still verify the file’s signature, hash, installation source, and process activity before dismissing it.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures