QuestionQ35

Incident Response and Management

A SIEM alert fires after a suspicious one-liner is executed on two workstations in the organization’s environment. An analyst reviews the event details below:

Question Image

Which statement best describes the attacker’s intent based on this one-liner?

Explanation

The one-liner launches PowerShell with an execution-policy bypass, downloads the content at AccessToken.ps1 through Net.WebClient.DownloadString, and supplies that content to IEX (Invoke-Expression) for execution. DownloadString retrieves a resource as a string, and Invoke-Expression evaluates and runs a specified command string.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!