CrowdStrike CCFR-201b Question Answer
A responder has identified a suspicious PowerShell script executing on a domain controller. To perform a deep-dive forensic analysis of every action taken by that specific process—including network connections and file modifications—the analyst needs to pivot to a Process Timeline. What is the absolute minimum telemetry data required to generate this auto-filled view?
CrowdStrike CCFR-201b Summary
- Vendor: CrowdStrike
- Product: CCFR-201b
- Update on: Jul 21, 2026
- Questions: 209

