Which Executive Summary dashboard item indicates sensors running with unsupported versions?
You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?
You notice that taskeng.exe is one of the processes involved in a detection. What activity should you investigate next?
According to the [Microsoft website], taskeng.exe is a legitimate Windows process that is responsible for running scheduled tasks. However, some malware may use this process or create a fake one to execute malicious code. Therefore, if you notice taskeng.exe involved in a detection, you should investigate whether there are any scheduled tasks registered prior to the detection that may have triggered or injected into taskeng.exe. You can use tools such as schtasks.exe or Task Scheduler to view or manage scheduled tasks.
Alberto
13 days agoLeeann
17 days agoReed
27 days agoRocco
1 months agoRebecka
1 months agoEffie
2 months agoLeota
3 months agoAudrie
3 months agoKasandra
4 months agoLashaun
4 months agoErick
4 months agoPatti
5 months agoShaniqua
5 months agoKerrie
6 months agoSheridan
6 months agoLynsey
6 months agoJacqueline
6 months agoReuben
7 months agoJill
7 months agoRonny
7 months agoBritt
7 months agoDonte
8 months agoUla
8 months agoTitus
8 months agoGrover
8 months agoRonnie
8 months agoDesirae
9 months agoDalene
9 months agoRonnie
9 months agoJohanna
9 months agoWava
9 months agoJenelle
10 months agoMitsue
10 months agoLuis
10 months agoTrinidad
10 months agoNgoc
10 months agoKati
11 months agoLillian
11 months agoMarkus
11 months agoToshia
1 years agoMaynard
1 years agoClarence
1 years agoLauran
1 years agoLang
1 years agoCaprice
1 years ago