You are using EnCase Endpoint Investigator to triage a suspicious endpoint. You need to identify unauthorized processes currently running. Which feature should you utilize?
Trap 1: File Signature Analysis.
This is used to verify file integrity, not check running processes.
Trap 2: Registry Analysis feature.
Registry analysis is for persistent configuration data, not current process state.
Trap 3: Event Log Collector.
Event logs are for historical analysis, not current process monitoring.
- A
Process List viewer.
This allows the responder to view currently running processes and their associated metadata.
- B
File Signature Analysis.
Why wrong: This is used to verify file integrity, not check running processes.
- C
Registry Analysis feature.
Why wrong: Registry analysis is for persistent configuration data, not current process state.
- D
Event Log Collector.
Why wrong: Event logs are for historical analysis, not current process monitoring.