Quiz 13 Question 10 of 20

A SOC analyst sees EDR telemetry showing PowerShell executing encoded commands on a Windows host, with no new file created on disk. To preserve evidence most likely to contain the active malicious code, which artifact should be collected first?

Select an answer to reveal the explanation.

Motivation