1
Security Operations
hard
An analyst is investigating a potential compromise on a Windows endpoint. EDR telemetry shows that 'powershell.exe' was launched by 'svchost.exe', which in turn was spawned by 'services.exe'. The analyst observes that 'powershell.exe' then executed a script that downloaded an executable. What should the analyst be most concerned about?