Riskware object

Prev Next

Riskware-object alerts indicate that the endpoint downloaded known riskware.

The endpoint should be investigated for the presence of riskware. If the end user knowingly downloaded the file but did not execute it, the endpoint might be clean. It is possible that the file was dropped and executed without the userʼs knowledge.

If the end user ran the binary, it is likely that the endpoint is compromised, unless the binary only works on certain software versions. In this case, the endpoint should be removed from the network for additional analysis. Check local security logs and SIEM logs. You can also use the Endpoint Security (HX) server for triage investigation.