You have a Microsoft 365 E5 subscription that contains a device named Device1. Device1 is enrolled in Microsoft Defender for Endpoint.
Device1 reports an incident that includes a file named File1.exe as evidence.
You initiate the Collect Investigation Package action and download the ZIP file.
You need to identify the first and last time File1.exe was executed.
What should you review in the investigation package?
wheeldj
Highly Voted 1 year, 2 months agowheeldj
1 year, 2 months ago281f173
Highly Voted 1 year, 2 months agoliveup2it
1 year, 1 month agosapphire
Most Recent 8 months, 2 weeks agosapphire
8 months, 2 weeks agog_man_rap
11 months, 1 week agoServerBrain
1 year, 2 months agoDChilds
1 year, 3 months agopk69
1 year, 3 months ago