Forum Discussion

retornet's avatar
retornet
Icon for Bronze II rankBronze II
2 months ago
Solved

APT29 Threat Hunting with Splunk: Ep.4 – Clean-up & Reconnaissance

I need help with Q6. Any hint please The attacker launches a PowerScript useful for reconnaissance activities. What is the full file path of the executed script? I searched (EventCode=4103 OR Eve...
  • retornet's avatar
    retornet
    2 months ago

    Found it at the end. Thanks