QuestionQ48

Threat Hunting Techniques

A company’s cybersecurity team analyzes a potentially malicious Microsoft Excel file and finds that it contains a hidden PowerShell command. The team must develop a playbook that generates alerts for Excel files whose hidden commands have been executed.

Which two techniques should the team use to accomplish this goal?

Choose two
Explanation

PowerShell execution logs, particularly script block logging, record PowerShell commands and scripts that are processed. Parent-child process telemetry identifies that Excel initiated the PowerShell process, allowing alerts to correlate the execution with the Excel file rather than unrelated PowerShell activity.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!