Does finding malware prove it was executed?¶
No. Finding a malicious file proves that the file was available in the place examined. It may have arrived as an attachment, download, backup copy or quarantined item without ever running.
Execution is a separate event. It needs evidence that the operating system loaded or started the code.
Follow one file into a process¶
Suppose Microsoft Defender identifies invoice-reader.exe in a Windows Downloads folder. The path and hash help identify the file, but they do not show whether anyone launched it.
On the same device, a Windows process-creation record resembling the following is much more useful. The record values below are simplified fictional teaching data:
The event connects the file's path and hash to a new process on the examined device at a recorded time. The parent process is consistent with launch from the Windows desktop shell. That is positive evidence of execution.
It does not, by itself, show which person launched the file or that every malware function succeeded. The account is the process security context; remote control, shared use or another launch route may still need testing.
Keep the two findings separate¶
| Finding | What it supports |
|---|---|
| File path, hash or detection | The file was present in the recorded location |
| Process or memory event tied to the file | The code was loaded or executed in the recorded context |
If execution is disputed, what evidence may show malware execution? covers process telemetry, memory, launch records and resulting activity in detail.
Read the security action literally¶
An alert saying blocked before execution supports a different conclusion from one saying process terminated. Quarantine may happen before or after a file runs, and a label such as remediated may summarise several actions. Preserve the underlying event, action, result, device, time, path, hash and any linked process identifier.
Absence of a process event should also be described carefully. Logging may have been disabled, retention may have expired, memory may have been lost, or containment may have removed traces. A negative search establishes what the available sources did not show; it does not automatically prove that execution was impossible.
Report the result at the level the records support: the file was present, or the file was executed in the recorded context. Any claim about what it then did belongs to the next evidential question.