CrowdStrike
CCFH-202B · Question #86
During an investigation you find out that files are being written to disc by a malicious process. While many are displayed in the detections as context items, you want to see all files written to…
The correct answer is A. event_simpleName=*written ComputerName=MyPC ContextProcessId_decimal=0123456789. You've hit your limit · resets 12:50am (America/New_York)
Threat Investigation and Hunting
Question
During an investigation you find out that files are being written to disc by a malicious process. While many are displayed in the detections as context items, you want to see all files written to your host by this process. What Splunk search would work for this scenario?
Options
- Aevent_simpleName=*written ComputerName=MyPC ContextProcessId_decimal=0123456789
- Bevent_simpleName=processrollup ComputerName=MyPC
- Cevent_simpleName=*written ComputerName=MyPC TargetProcessId_decimal=0123456789
- Devent_simpleName=processrollup ComputerName=MyPC
How the community answered
(22 responses)- A82% (18)
- B5% (1)
- C5% (1)
- D9% (2)
Explanation
You've hit your limit · resets 12:50am (America/New_York)
Topics
#file write events#ContextProcessId_decimal#process investigation#malware hunting
Community Discussion
No community discussion yet for this question.