You’re wasting valuable time manually looking for data exfil and powershell.
Cyber Triage automatically does this (and more).
I showed how in our webinar last week and the video is up. Watch today for faster investigations.
New "DFIR Next Steps" post on what to do after you find certutil being using during your investigation timeframe.
Mike covers verifying it's malicious, what must have happened for them to run it, and what to look for next.