You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
Sherell
2 days agoAlverta
5 days agoToi
6 days agoThurman
9 days agoAlverta
12 days ago