MEDIUM Suspicious Process Creation

RESOLVED SECURITY TESTING ID: #1157 | Created: 2026-01-10 10:39:23
1
Alerts
1
Hosts
2
Files
0
Network
Incident Overview

Suspicious process creation detected

1
2026-01-10 12:07
Unassigned
XDR Agent
Malware
Affected Hosts & Users
ubuntu
MITRE ATT&CK Mapping
No MITRE ATT&CK data available for this incident
File Artifacts 2
File Name Path SHA256 Signature Verdict Actions
regsvr32.exe - f379c637eb2250f0cdae05918035a37f3fdf89d6b2ad897da235c5f603fe2a1e SIGNATURE_SIGNED UNKNOWN VT
cmd.exe - 64afc6db3aad1289533662e2d79e27dd55c7dcdb8cd918b08e145ad82ad5acb4 SIGNATURE_SIGNED UNKNOWN VT
Network Artifacts 0
No network artifacts found for this incident
Process Artifacts 1
Process Command Line Parent Process User
cmd.exe "cmd.exe" /c "C:\Users\ubuntu\AppData\Local\Temp\xdr_test_0fcd40d069944f39940d36... - ubuntu
Registry Artifacts 0
No registry artifacts found for this incident
Analyst Verdict
MEDIUM
Bulk resolved via XdrTestManager IncidentLive
  • Monitor for similar activity
  • Verify remediation complete
Summary
1
Alerts
1
Hosts
2
Files
0
Network
Alert Categories
Malware
Timeline
01-10 12:07:40
Incident Modified
Status or details updated
01-10 12:07:40
Incident Resolved
resolved security testing
01-10 10:39:23
Incident Created
#1157 - Suspicious Process Creation
01-10 10:39:23
regsvr32.exe
Verdict: Unknown
01-10 10:39:23
cmd.exe
Verdict: Unknown
01-10 09:25:19
Suspicious Process Creation
medium - Prevented (Blocked)