- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-10-2023 12:45 AM - edited 06-10-2023 12:54 AM
Hi, we have recently malware scanned an endpoint and upon checking the results, it appears that there were 3 malicious files on the host.
Now, I tried to right click and view related alerts on the 3 malicious files and it just shows nothing. What's weird about this is it showing MD5 hashes on External ID field. I checked those hashes via ThreatVault and VirusTotal and it doesn't give any results.
Now my question is how are we suppose to track the 3 malicious files as per malware scan when we have no idea what it is and Cortex showing not enough insight. Checking the historical incidents on this host in regards of malicious files, I only see one WildFire related incident for the past few months.
Thank you!