Malware callback (DTI.callback)

Prev Next

This alert indicates that the endpoint generated suspicious traffic and the MVX engine returned a positive match. Zero-day callbacks are only enabled on Dynamic Threat Intelligence (DTI) two-way licenses because data must be sent to DTI to validate this threat. The endpoint is likely compromised because standard browsing traffic will not trigger this type of dynamic alert. The endpoint should be investigated immediately and removed from the network during the process. Check local security logs and SIEM logs. You can also use the Endpoint Security (HX) server for triage investigation.