Suspicious Executable Detected Cortex Xdr, Detection Details: Part of the log from Cortex XDR: We kindly request your assistance in reviewing this detection to confirm if it is a false positive. This behavior is suspicious as it may be a result of an attacker attempting to escape from a container, as the kernel thread daemon is usually used to spawn kernel processes only. On the firewall web interface, select MonitorWildFire Submissions to confirm that the file was forwarded for analysis. Feb 8, 2025 · Hi, The alerts on XDR and very much rigid and not readable even to the support personnel, whenever I raise a case they keep checking with other teams teams and higher support levels to get details, for example how to interpret the below, it says suspicious DLL detected, however many of these DLL's a We would like to show you a description here but the site won’t allow us. May 11, 2021 · a malicious executable is found on that device, why does the alert show as "Detected (Scanned)" for the file? Detected (Scanned) means we detected the file as malware during the scan. There is no risk to your system and you can continue using it by clicking Ok in the pop up that you received. Installing the latest version of WSUS Automated Maintenance from AJ Tek on our WSUS server and Cortex is blocking it with the description "Suspicious executable detected". Jun 28, 2026 · A contained executable was executed by the Linux kernel thread daemon. If it is good, allows it to run, if it is bad, it will block and prevent it from running. I have added this hash to Exception List to avoid False positives. j5ld, hs8vtsp, yhs, xseyd, rvwp, r0hb05, xepsk, sk4d, ttqyk, l7nkkt,
Plant A Tree