cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

Why there are no related alerts on scanned malicious files.

L1 Bithead

Hi, we have recently malware scanned an endpoint and upon checking the results, it appears that there were 3 malicious files on the host.

2023-06-10 15_39_58-Action Center - Cortex XDR.png

Now, I tried to right click and view related alerts on the 3 malicious files and it just shows nothing. What's weird about this is it showing MD5 hashes on External ID field. I checked those hashes via ThreatVault and VirusTotal and it doesn't give any results.

aaronquiamco_0-1686382887819.png

Now my question is how are we suppose to track the 3 malicious files as per malware scan when we have no idea what it is and Cortex showing not enough insight. Checking the historical incidents on this host in regards of malicious files, I only see one WildFire related incident for the past few months.

 

Thank you!

Who Me Too'd this topic