An incident response analyst is investigating the root cause of a recent malware outbreak. Initial binary analysis indicates that this malware disables host security services and performs cleanup routines on its infected hosts, including deletion of initial dropper and removal of event log entries and prefetch files from the host. Which of the following data sources would most likely reveal evidence of the root cause? (Choose two.)
Kmelaun
Highly Voted 1 year agokinny4000
7 months agofuzzyguzzy
Most Recent 5 months agocy_analyst
7 months agocy_analyst
6 months, 3 weeks agokinny4000
7 months agoSH_
7 months, 2 weeks agosection8santa
1 year, 1 month agoRottenBarracuda
1 year, 1 month agoBogus1488
1 year, 1 month agoFranky30
1 year, 1 month agoTdarling77
1 year, 1 month agoJhonattan0032
1 year, 2 months agojspecht
1 year, 2 months ago