Hello everyone,
I am opening this topic to report a persistent false positive issue involving Google Antigravity and SentinelOne Agent (EDR) on Windows 11.
Environment:
- OS: Windows 11 (Latest build)
- Security Software: SentinelOne Agent
- Applications : Antigravity 2.0 , Antigravity CLI, Antigravity IDE , Antigravity SDK
The Problem:
SentinelOne’s behavioral AI engine actively blocks and quarantines Antigravity upon execution. It triggers an alert flagging the application as a “Ransomware” threat.
This behavioral detection is highly likely caused by Antigravity’s multi-agent architecture specifically its background orchestrations, automated command executions, and rapid local file creation/modification, which mimic ransomware heuristic patterns.
Current Constraints:
In our enterprise environment, IT administrators apply a strict zero-trust policy. Because the EDR triggers a high-severity ransomware alert, they refuse to create a local path or hash exclusion manually until the file’s reputation is cleared globally.
Request:
Could the Google Antigravity team please look into this behavior?
Ideally, it would be great if you could:
- Review the application’s API calls (background tasks, rapid file system writes) to mitigate these ransomware heuristic triggers.
- Coordinate with SentinelOne Labs / Threat Intelligence to update the global cloud reputation and whitelist the binary hashes for recent versions of Antigravity.
Thank you for your help and for keeping this amazing tool moving forward!