Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

EDR: “(Unknown)” Events in Process Search Results

EDR: “(Unknown)” Events in Process Search Results

Environment

  • EDR Server: All Versions

Symptoms

  • Occasionally a process will appear in search results with the name "(unknown)".
  • The process graph may show the parent as "top"
  • Process Start Time is similar to 1969-12-31T23:59:59:999Z
  • PID is -1

Cause

The "(Unknown)" Events appearing on a Process Search is expected. This "(Unknown)" process was already running at the time the sensor was installed on the host.

Resolution

  • Because the sensor was not aware of the start and execution of these events, not all of the metadata is available such as process name or start time. This will result in the Process showing as "(Unknown)" and the Start Time will be inaccurate.
  • Often these "(Unknown) processes will spawn children after the sensor is running. The child processes may contain metadata that will include information about the "(Unknown)" parent process, such as parent_name, that could provide additional insight during an investigation.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
0% helpful (0/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
1049
Contributors