Why is security software generating so many false alerts?
Endpoint security software frequently creates severe alert fatigue by flooding systems with thousands of noisy warnings and heavy CPU usage. This constant disruption causes system performance issues, conflicts with background services like the search indexer, and forces administrators to repeatedly restore servers from backups.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Replacing the endpoint security software with alternatives like Huntress combined with Windows Defender or Defender for Endpoint (DfE)
- 2Creating policy overrides, exclusions, and custom rules to attempt to stop alert fatigue
In their words
Unedited, most upvoted first, each linked to the thread it came from.
“No product is perfect but after having to restore servers from backup several times and the Dell software generating thousands of alerts despite an S1 "mitigation" I've had enough.”source ↗
“We started doing this last year.. S1 blowing up our RMM with no explanation or fix from S1.”source ↗
“I too am getting frustrated with the noise that is S1. Constant CPU and disk hog and conflicts with the search indexer service.”source ↗
Where this came up
People with this problem also raised
- 5Antivirus blocking legitimate software updates and installers
- 3Why does software installation fail on secure systems?
- 6Why are security warning emails so vague?
- 6Why does Microsoft Edge force ads and unwanted features?
- 3Why does security software lock out the entire organization?
- 13Why am I seeing ads in software I already paid for?