Review the following search:childproc_name:`rundll32.exe` AND -digsig_result:`Signed` AND path:c:\windows\*What is this search looking for?
Which reputation is processed with the lowest priority for Endpoint Standard?
Which statement is true about Carbon Black Live Response (CBLR)?
Management has directed that the SOC team be enabled to create global file bans via the App Control API.How would this be configured in the App Control Console?
An administrator is creating a query per policy for Audit and Remediation. The administrator ran several recommended queries already but notices they are unable to run the same recommended query for one of their policies. The run button is grayed out.Which statement correctly explains why the run button is unavailable?
An analyst has investigated two alerts on two separate HR workstations and found that notepad.exe has established communication to another IP address.Which rule will kill notepad.exe entirely if this activity is detected in the future?