After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?
Aside from a Process Timeline or Event Search, how do you export process event data from a detection in .CSV format?
When analyzing an executable with a global prevalence of common; but you do not know what the executable is. what is the best course of action?