Quiz 2 Question 15 of 20

A Windows endpoint begins executing PowerShell commands that download a second-stage payload, spawn a new process, and inject code into a legitimate svchost.exe process. Which EDR capability is MOST critical for detecting this fileless attack chain?

Select an answer to reveal the explanation.

Motivation