Your environment has several PowerShell scripts running that are Base64 encoded. Which of the following areas of Falcon will show you the decoded PowerShell commands?
A.
PowerShell Encoded Commands report
B.
PowerShell Hunt report
C.
Event Search for event_simpleName=processrollup2 FileName=powershell.exe
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
alanalanalan
3 months, 4 weeks ago