Forum Discussion
kevinh
21 days agoBronze III
APT29 Threat Hunting with Splunk: Demonstrate Your Skills - Question 10
In relation towards the question : A PowerShell script was initially executed to extract encoded data from an image file. What is the full ParentCommandLine field value used to execute this? I am p...
- 19 days ago
nevermind, I just had to parse for powershell commands with image file extensions, with the help of Gemini
kevinh
19 days agoBronze III
nevermind, I just had to parse for powershell commands with image file extensions, with the help of Gemini