Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Enterprise EDR: Group by Hash not working on Process Analysis page

Enterprise EDR: Group by Hash not working on Process Analysis page

Environment

  • Enterprise EDR Console: All Versions

Symptoms

Investigate page is set to "Group by hash", but several processes of the same name / hash are listed individually

Cause

The current logic to group hashes will not group any processes that are tied to a watchlist hit or with child processes

Resolution

The current behaviour is by design. Future work will improve the logic to include watchlist events and events with children - DSER-25387

Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎02-11-2021
Views:
196
Contributors