Quiz 9 Question 16 of 20

An EDR solution reports that a process (winword.exe) spawned a child process (cmd.exe) which then ran 'powershell.exe -nop -w hidden -enc <base64>'. What attack technique is most likely being executed?

Select an answer to reveal the explanation.

Motivation