cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
86
Views
0
Helpful
0
Replies

log entries re [ExecHandler.swift@335] ... "hash found in cache!"

bobstowe
Level 1
Level 1

In trying to investigate the source of a Mac Book M4 Pro crash that made the trackpad unresponsive to clicks, and also killed the Dock and Application Switcher, I found multiple log entries on my Mac (running Sequoia 15.6.1) of the form “com.cisco.endpoint.svc.securityextension [info][ExecHandler.swift@335] Executable file /usr/libexec/xpcproxy - hash found in cache!”,

 and
”endpointsecurity [info][ExecHandler.swift@335] Executable file /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/Metadata.framework/Versions/A/Support/mdworker_shared - hash found in cache!”

Does “hash found in cache!” from com.cisco.endpoint.svc.securityextension refer to it finding the hash of a potentially malicious file?  I have scanned what I believe are the relevant cache files and binaries with several antivirus engines, and did not get any hits. I do have reason to suspect that I might have been hacked by some sophisticated and malign actors, and I cannot find any matches to "ExecHandler.swift@335" (or even "swift@335") on the web (although perhaps ExecHandler.swift is a component of the Endpoint Security Extension?). Thanks.

0 Replies 0