Courseiva

SecOps-Pro

Study mode — explanations shown

1

Cortex XDR

medium

You are creating a custom BIOC rule to detect suspicious PowerShell execution. The rule must trigger when PowerShell is executed with an encoded command. Which field should you focus on in the rule builder?

0 of 25 answered