You are a SOC analyst at an organization that uses Google Security Operations (SecOps). You are investigating suspicious activity in your organization’s environment. Google SecOps alerts show repeated PowerShell activity on a group of endpoints. Outbound connections are being made to a domain that is absent from your threat intelligence feeds. The activity takes place across multiple systems and user accounts. You must search across affected systems and user identities to identify the malicious user and determine the scope of the compromise. What should you do?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion