EDR in iCDM Incidents triggered with 8027 events show processes are still running, when they are not
Article ID: 191461
Endpoint Detection and Response Cloud
When reviewing Memory Exploit Manager Incidents that include type_id 8027 events, the animation makes it appear that several processes are still running.
Endpoint Activity Recorder does not get process termination events for these executables. As a result, the Lineage view animates the node as "currently running", which is false/misleading:
The functionality for these feedback events is not currently available. This will be addressed in a future release.