May 14, 2023, 7:42 p.m. | /u/xbadazzx

cybersecurity www.reddit.com

Hey wanted some clarification from the crowd. I was trained when searching for example someone executing blah.exe


CmdLine should cover everything whether it's under srcproccmd,tgt,parent etc..

that's not the case at times, we still need to revert to srcprocscript contains blah.exe.

what's the general rule when you guys are searching? normally we're looking for people using cmd or powershell using LOL techniques like cscript > .js

case crowd cybersecurity etc general hey people search sentinelone under

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC