LevelBlue False Positive Removal (AlienVault / AT&T)
By Glenn Lyvers · Updated · 6 min read
If VirusTotal shows LevelBlue flagging your website, the fastest fix is LevelBlue’s own VirusTotal detection review form — but only after you have confirmed the site is actually clean. LevelBlue is the security company spun out of AT&T Cybersecurity, and it owns the old AlienVault threat-intelligence business, which is why you may see “LevelBlue” and “AlienVault” in the same report.
Who LevelBlue is, and why the name keeps changing
LevelBlue launched in May 2024 as a joint venture between AT&T and the investment firm WillJam Ventures, taking over what used to be AT&T Cybersecurity. That business already included AlienVault, which AT&T bought in 2018, and with it the Open Threat Exchange (OTX), a large community threat-sharing platform. In 2025 LevelBlue kept buying: it completed the acquisition of Trustwave in August 2025, took over Aon’s Stroz Friedberg consulting group the same month, and closed its purchase of Cybereason in December 2025.
For a website owner, the corporate history matters for one practical reason: the same organization now sits behind several names you may meet in a scan result. If you are also seeing a Trustwave or Cybereason verdict, those still have their own routes — see my Trustwave removal steps and Cybereason removal steps.
LevelBlue and AlienVault are two separate rows on VirusTotal
VirusTotal’s published list of URL and domain engines includes both alienvault and levelblue as distinct entries. That means a single site can be flagged by one, by the other, or by both, and clearing one does not automatically clear the other.
| What you see on VirusTotal | Where the verdict comes from | Where to dispute it |
|---|---|---|
| LevelBlue | LevelBlue’s URL detection engine | LevelBlue’s VirusTotal detection review form |
| AlienVault | OTX indicator data (community pulses and reputation) | OTX, through a logged-in account |
If you are not sure how to read a VirusTotal report in the first place — which rows carry weight and which are machine-learning guesses — my guide to VirusTotal detection labels covers that before you spend time on any single vendor.
Step 1: confirm the site is actually clean
Every vendor review works the same way: someone, or something, fetches your URL and looks at what it serves. If the injected script or the spam folder is still there, the request is refused, and repeated refusals make the next one harder. So check before you file.
- Run the site through my free site scanner, and check the other lists at the same time with the free blacklist checker.
- Load the site from a phone and from a Google search result, not just by typing the address. Conditional malware hides from logged-in owners and direct visits — my guide on what a hacked site actually looks like lists the usual tells.
- Look for files you did not create, particularly
.phpfiles inwp-content/uploads/, and for script tags in your header that load from domains you do not recognize. - If you use a CDN, purge it. A clean origin behind a poisoned cache still serves the bad response to the reviewer.
If anything turns up, clean it and close the way in first. The flag is a symptom; the infection is the problem.
Step 2: submit LevelBlue’s VirusTotal detection review
VirusTotal does not make verdicts of its own and cannot remove a vendor’s detection for you. VirusTotal’s contributors list points LevelBlue disputes to a dedicated page: support.levelblue.com/virustotal-detection-review/.
- Enter a working email address. LevelBlue says it is used only for tracking and questions about the request.
- Enter the exact URL VirusTotal shows as flagged. If the whole domain is flagged, use the bare domain; if a single path is flagged, use that path.
- In the comments field, say briefly what you found and what you fixed, or why you believe the detection is wrong. One or two factual sentences beat a page of protest.
- Submit once.
Two things to know about that form. LevelBlue states that requests are reviewed within two business days, and it also states that it cannot send email confirmations — so silence after submitting is normal, not a sign the form failed. Re-check the VirusTotal report after a couple of business days, and use VirusTotal’s reanalyze button so you are not looking at a cached verdict. The form is for VirusTotal detections only; the page links a separate generic URL submission form for anything else.
Step 3: if AlienVault / OTX is also flagging you
An AlienVault row on VirusTotal usually reflects OTX indicator data: your domain or URL appears in one or more community “pulses”. Look your domain up on otx.alienvault.com to see which pulses reference it. False-positive submissions on OTX are made from a logged-in account, so create a free account first. Reference the pulse and the indicator, and state what the site is and why the listing is wrong.
Be realistic about pulses. They are written by community members, and some are bulk dumps of every domain seen in a phishing kit or a sandbox run — legitimate CDNs and ordinary sites get swept in. That is a genuine false-positive case. But a pulse that names a specific file path on your site, such as /wp-content/uploads/2026/03/login.php, is usually describing something that really was there.
Want the warnings gone without the paperwork?
Clearing a flag means cleaning the cause and then working each vendor's own queue. I do both.
Not sure which? Ask me first — I’ll tell you honestly if you can handle it yourself.
If the LevelBlue flag comes back
A detection that returns within days of being cleared is almost never the vendor changing its mind. It is re-detection: a backdoor survived the first cleanup and the payload was put back. The usual survivors are a rogue admin user, a malicious mu-plugin, a scheduled task in the database, or a web shell with an innocent filename. My reinfection guide goes through where each one hides, and the backdoor removal guide covers finding them.
This is the point where hand-cleaning stops being cheap. If you have cleaned twice and been flagged twice, let me do the cleanup — I find what keeps putting it back, file the vendor reviews, and the work carries a 60-day guarantee.
Check the rest of the list while you wait
A site flagged by LevelBlue is rarely flagged by LevelBlue alone. Open the full VirusTotal report and note every engine with a verdict, then work through them together — each keeps its own list with its own form. My website blacklist check guide lists every major vendor’s lookup tool, and the vendor removal directory has the official dispute route for over 100 of them. If Google Safe Browsing is on that list, deal with it first; it does far more damage than any single engine, and my Safe Browsing removal steps cover it.
Common questions
Is LevelBlue the same company as AlienVault?
Effectively, yes. AT&T bought AlienVault in 2018 and folded it into AT&T Cybersecurity, which became LevelBlue in May 2024. On VirusTotal, however, LevelBlue and AlienVault appear as two separate engines, so a site can be flagged by one and not the other. Dispute each verdict through its own route.
How long does LevelBlue take to review a false positive?
LevelBlue says requests through its VirusTotal detection review form are reviewed within two business days. It also says it cannot send email confirmations, so you will not get an acknowledgment. Re-check the VirusTotal report after a couple of business days and use the reanalyze button to avoid seeing a cached result.
Can VirusTotal remove the LevelBlue detection?
No. VirusTotal only aggregates results from vendors and does not produce verdicts of its own. The detection has to be corrected by LevelBlue. Once LevelBlue updates its data, a fresh VirusTotal analysis of your URL will show the change.
Why is LevelBlue flagging my website?
Usually because something on the site is, or recently was, malicious: an injected script, a phishing page in a folder you never created, or a redirect that only fires for some visitors. Genuine false positives also happen, especially on new domains or shared IP addresses. Check the site properly before assuming either.
Does a LevelBlue detection affect my Google rankings?
Not directly. LevelBlue is not a search engine, and its verdicts are not Google ranking signals. The indirect damage is real, though: security products that consume its data can block your visitors, and the same infection that tripped LevelBlue often trips Google Safe Browsing, which does hurt your search traffic.
Does clearing Trustwave also clear LevelBlue?
Don't count on it. LevelBlue acquired Trustwave in 2025, but the products and removal routes were built separately and are not documented as shared. If both flag you, submit to both and check each result independently.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.