Skip to main content
Tier One
Medium

EICAR test file detected during antivirus validation

A-1046

00:00time on this alert, target 20 minutes

Back to queue

Alert details

Source
EDR
Detection rule
EDR-MALWARE-SIGNATURE-030
Affected user
a.brennan
Affected host
WKS-ENG-07
Source IP
First seen
2026-07-24T14:02:00Z

Why this fired, in plain English

The antivirus signature database matched a known-bad file pattern.

Suggested playbook

Malware detection on an endpoint

  1. 1. Read the action field first: blocked/quarantined changes urgency dramatically versus alert_only.
  2. 2. Identify the process path. AppData, Temp and Users\Public are common malware locations.
  3. 3. Check the parent process — Office apps spawning shells is abnormal.
  4. 4. Look up the file hash for a verdict and first-seen date.
Open the full checklist

Raw log evidence

Exactly what the tools recorded — 3 events.

  1. Guided hint: this line matters

    ts=2026-07-24T14:01:12Z host=WKS-ENG-07 sensor=edr event=file_write path="C:\\Temp\\av-validation\\eicar.com" user="a.brennan" sha256=275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f

    EICAR is a harmless industry-standard test string used to check that antivirus is working.

  2. Guided hint: this line matters

    ts=2026-07-24T14:01:13Z host=WKS-ENG-07 sensor=edr event=detection signature="EICAR-Test-File" action=quarantined path="C:\\Temp\\av-validation\\eicar.com"

    action=quarantined means the file was already removed automatically.

  3. Guided hint: this line matters

    ts=2026-07-24T13:59:40Z src="itsm" event=change_window ticket="CHG-4471" summary="Quarterly EDR validation on engineering fleet" approver="s.bell" window="2026-07-24T13:30Z/2026-07-24T15:00Z" assignee="a.brennan"

    There is an approved change ticket covering exactly this activity, this host and this time window.

Related events

The order things happened in.

  1. 13:59Z

    Change window CHG-4471 opens

  2. 14:01Z

    EICAR written and quarantined

Enrichment lookups

Mock lookups. Run each one yourself — a real analyst never guesses what a lookup would have said. There is no "run everything" button on purpose.

0 of 4 lookups checked
  • Not checked yet.

  • Not checked yet.

  • Not checked yet.

  • Not checked yet.

techniques

Your verdict

Keyboard shortcuts 1–4, or click. You can always change your mind afterwards.