Views:

The falsely detected file is %PROGRAMFILES(x86)%\Trend Micro\Endpoint Basecamp\EndpointBasecamp.exe.

According to currently reported cases, Cisco AMP detected it by the rules named PE Contains an Invalid Certificate Signature and PE Contains A Suspicious Certificate Signature, as shown in the sample below:

Behavioral Indicators

Behavior Indicator

In order to keep Apex One agent working correctly, it is suggested to add this file into the exception list of third-party software.

For more information about Endpoint Basecamp, you can refer to What is Trend Micro Endpoint Basecamp?.