An event graph associated with a root cause for a change in security state on an endpoint is used to facilitate malware detection on other endpoints.