Forum Discussion
kevinh
3 days agoBronze III
APT29 Threat Hunting with Splunk: Demonstrate Your Skills - Question 10
In relation towards the question : A PowerShell script was initially executed to extract encoded data from an image file. What is the full ParentCommandLine field value used to execute this? I am p...
- 22 hours ago
nevermind, I just had to parse for powershell commands with image file extensions, with the help of Gemini
kevinh
22 hours agoBronze III
nevermind, I just had to parse for powershell commands with image file extensions, with the help of Gemini