Hello,
Yes. The recommended approach is to create a narrowly scoped exception for the trusted update source rather than disabling the Suspicious File Download signature globally.
If the binary packages are coming from a known vendor, allowlisting based on the vendor's download URL, FQDN, certificate reputation, or file hash is typically the safest option. This preserves inspection and protection for all other downloads while permitting the specific update traffic.
Before creating an exception, verify that the files are digitally signed by the expected vendor and confirm their hash values. If your security appliance supports policy-based exceptions, limit the exemption to the specific destination, application, file type, or update server. Avoid broad rules such as allowing all executable downloads, as this significantly reduces security coverage.
Also review whether the signature is generating a false positive or whether a more recent signature package, threat database update, or firmware version is available for the appliance. In many cases, updating the security signatures resolves incorrect detections without requiring permanent exceptions.
The exact configuration depends on the security platform in use. If you can provide the appliance vendor and model (for example Palo Alto, FortiGate, Check Point, Cisco, Sophos, etc.), I can provide the precise recommended configuration method.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
Domic Vo.