Malware scan results

Prev Next

Clicking on a value in the # of Malware column opens the Malware Scan Results page. This page displays details about the malware detected on the host endpoint. You can download malware scan results as a .csv file by clicking the download (csv-dwnld.png) icon in the right corner of the page.

The following table describes the details shown in Malware Scan Results. Some data is not provided for some types of malware.

Field

Description

Malware Name

The name of the malware threat that was detected by the scan on your host endpoint. You can search or filter on this field.

Infection Type

The type of malware infection: Malware, Adware, PUP, or Spyware. You can search or filter on this field.

Object Scanned

The type of object scanned: File. You can search or filter on this field.

Path

The file location on the host where the threat was found.

MD5

The MD5 checksum for the detected threat.

Action Taken

The action taken on the infection: Alert, Clean, or Quarantine. You can filter on this field.

The Malware Scan Results page also includes details of the malware engine and AV engine that performed the scan.

Note

The n threats detected value in the left corner of the Malware Scan Results page may differ from the actual number of threats detected on the host. This mismatch can be caused by a number of factors, including alert deduplication on the host, alert rate limiting, alerts aging out, and user actions such as marking alerts as false positive or deleting alerts.

Acquisitions

Acquisitions for the host are listed at the bottom of the page.

HostAcqList.png

Click the acquisition to see the Acquisitions detail page and perform an action on that acquisition.

  • Select Download Full Triage to download a triage acquisition file.

  • Select Triage Summary to open a triage in the Triage Summary.

  • Select View Data Acquisition to review the acquired data in the Audit Viewer.

  • Select Process Data Acquisition to acquire process data for the host endpoint.

  • Select Download to download an acquired file.