MultipleChoice
Examine the following EDR query:
file_desc:''Windows Command Processor'' AND -process_name:cmd.exe
Which process will show in the query results?
OptionsMultipleChoice
Review the following search:
childproc_name:''rundll32.exe'' AND -digsig_result:''Signed'' AND path:c:\windows\*
What is this search looking for?
OptionsMultipleChoice
Which action is only available for the ''Performs any operation'' and ''Performs any API Operation'' operation attempts?
OptionsMultipleChoice
Review the following query:
path:c:\program\ files\ \(x86\)\microsoft
How would this query input term be interpreted?
Options