You notice that taskeng.exe is one of the processes involved in a detection. What activity should you investigate next?
Answer : C
According to the [Microsoft website], taskeng.exe is a legitimate Windows process that is responsible for running scheduled tasks. However, some malware may use this process or create a fake one to execute malicious code. Therefore, if you notice taskeng.exe involved in a detection, you should investigate whether there are any scheduled tasks registered prior to the detection that may have triggered or injected into taskeng.exe. You can use tools such as schtasks.exe or Task Scheduler to view or manage scheduled tasks.
When examining raw event data, what is the purpose of the field called ParentProcessld_decimal?
A list of managed and unmanaged neighbors for an endpoint can be found:
How long are quarantined files stored on the host?
What happens when a hash is set to Always Block through IOC Management?
What types of events are returned by a Process Timeline?