Forum Discussion

kevinh's avatar
kevinh
Bronze III
3 days ago
Solved

APT29 Threat Hunting with Splunk: Demonstrate Your Skills - Question 10

In relation towards the question : A PowerShell script was initially executed to extract encoded data from an image file. What is the full ParentCommandLine field value used to execute this? I am p...
  • kevinh's avatar
    22 hours ago

    nevermind, I just had to parse for powershell commands with image file extensions, with the help of Gemini