1
Cortex XDR
medium
You are creating a custom BIOC rule to detect suspicious PowerShell execution. The rule must trigger when PowerShell is executed with an encoded command. Which field should you focus on in the rule builder?
SecOps-Pro
Study mode — explanations shown
Cortex XDR
You are creating a custom BIOC rule to detect suspicious PowerShell execution. The rule must trigger when PowerShell is executed with an encoded command. Which field should you focus on in the rule builder?