If this is seen in the Console, you can Search by the Hash on the Device to see what occurred and verify the Sensor is Terminating / Denying the process when able.
Signs in the CBC Console that malware started before the Sensor:
- The Events show Reputation values that should have been Terminated / Denied but there was no action logged for this
- If the first Event for an Alert ID is services.exe invoking a process with a Reputation that should be stopped by Policy settings but is not
- If the Events of Known Malware running all occur in the same second
If unsure, please open a Support case for assistance.