An incident response analyst is investigating the root cause of a recent malware outbreak. Initial binary analysis indicates that this malware disables host security services and performs cleanup routines on its infected hosts, including deletion of initial dropper and removal of event log entries and prefetch files from the host. Which of the following data sources would most likely reveal evidence of the root cause? (Choose two.)
Kmelaun
Highly Voted 1 year, 2 months agokinny4000
8 months, 3 weeks agocj207800
Most Recent 3 weeks, 3 days agoJustheretolook
1 month agofuzzyguzzy
6 months, 3 weeks agocy_analyst
8 months, 3 weeks agocy_analyst
8 months, 1 week agokinny4000
8 months, 3 weeks agoSH_
9 months, 1 week agosection8santa
1 year, 2 months agoRottenBarracuda
1 year, 2 months agoBogus1488
1 year, 3 months agoFranky30
1 year, 3 months agoTdarling77
1 year, 3 months agoJhonattan0032
1 year, 4 months agojspecht
1 year, 3 months ago