Quiz 3 Question 2 of 20

An SOC analyst needs a portable detection for suspicious PowerShell encoded commands in Windows event logs. The rule must be reusable across the SIEM by translating it into native queries. Which artifact should the analyst author?

Select an answer to reveal the explanation.

Motivation