MEDIUM Suspicious Process Creation

RESOLVED SECURITY TESTING ID: #1177 | Created: 2026-01-10 12:12:13
1
Alerts
1
Hosts
2
Files
0
Network
Incident Overview

Suspicious process creation detected

1
2026-01-10 12:31
Unassigned
XDR Agent
Malware
Affected Hosts & Users
dwshin
MITRE ATT&CK Mapping
No MITRE ATT&CK data available for this incident
File Artifacts 2
File Name Path SHA256 Signature Verdict Actions
powershell.exe - 0ff6f2c94bc7e2833a5f7e16de1622e5dba70396f31c7d5f56381870317e8c46 SIGNATURE_SIGNED UNKNOWN VT
UltimateXdrGenerator.exe - 64affb2786b4cf64498dd4ddccee413981902611a07d1b38045ec03fa1397504 SIGNATURE_UNAVAILABLE UNKNOWN VT
Network Artifacts 0
No network artifacts found for this incident
Process Artifacts 1
Process Command Line Parent Process User
UltimateXdrGenerator.exe "C:\cortex-xdr-siem-test\xdr_tools\UltimateXdrGenerator\bin\publish\UltimateXdrG... - dwshin
Registry Artifacts 0
No registry artifacts found for this incident
Analyst Verdict
MEDIUM
Bulk resolved via XdrTestManager IncidentLive
  • Monitor for similar activity
  • Verify remediation complete
Summary
1
Alerts
1
Hosts
2
Files
0
Network
Alert Categories
Malware
Timeline
01-10 12:31:57
Incident Modified
Status or details updated
01-10 12:31:57
Incident Resolved
resolved security testing
01-10 12:12:13
Incident Created
#1177 - Suspicious Process Creation
01-10 12:12:13
powershell.exe
Verdict: Unknown
01-10 12:12:13
UltimateXdrGenerator.exe
Verdict: Unknown
01-10 12:12:08
Suspicious Process Creation
medium - Prevented (Blocked)