Resolved! Process Hunting - Powershell + WGET typing manualy
Hello dear community,
is there a way to hunt for a manually started powershell.exe where a attacker started wget.
In this case I opened cmd and typed this CMD in. Cortex XDR recognized it.
But when I manualy open powershell and type in manualy wg
...