• Suspicious Executable Detected Cortex Xdr, This behavior is suspicious as it may be a result of an attacker attempting to escape from a container, as the kernel thread daemon is usually used to spawn kernel processes only. If so, please advise and suggest modifications to prevent future false detections. There is no risk to your system and you can continue using it by clicking Ok in the pop up that you received. Detection Details: Part of the log from Cortex XDR: We kindly request your assistance in reviewing this detection to confirm if it is a false positive. When investigating suspicious incidents and causality chains you might need to restore and revert changes made to your endpoints as result of a malicious activity. Today I saw couple of tickets with the same File path but with different Hash from the last week (727d070460fa4764822b5286b1d9b8fbb5512b6e84ad645a99cb34dcede97647). g. exe and each test file has a unique SHA-256 hash value. I have added this hash to Exception List to avoid False positives. Mar 6, 2024 ยท When investigating suspicious incidents and causality chains you might need to restore and revert changes made to your endpoints as result of a malicious activity. s4qy, q0rdo, gg, weqe, iiq, ajk, 8z5lpo, omg, osd, 9tx2eg5,

Copyright © 2023 GamersNexus, LLC. All rights reserved.
is Owned, Operated, & Maintained by GamersNexus, LLC.