logo

Crowdly

Browser

Add to Chrome

You are working as a SOC analyst and receive an alert from your SIEM indicating ...

✅ The verified answer to this question is available below. Our community-reviewed solutions help you understand the material better.

You are working as a SOC analyst and receive an alert from your SIEM indicating the execution of a PowerShell command on a user workstation. Further investigation reveals that the command silently downloads a script from a remote IP and executes it in memory without writing to disk. You suspect this may be part of a living-off-the-land technique used by advanced attackers.How does the MITRE ATT&CK framework most effectively assist in analyzing this situation?
More questions like this

Want instant access to all verified answers on moodle.polytechnic.bh?

Get Unlimited Answers To Exam Questions - Install Crowdly Extension Now!

Browser

Add to Chrome