Pergunta de entrevista da empresa FireEye

How would you know when the malware got on the system?

Respostas da entrevista

Sigiloso

1 de mar. de 2016

MFT Table

1

Sigiloso

16 de mar. de 2016

The MFT is one way but that requires a forensic look at a drive. Not much help if the machine has a virus running in memory that never hit the physical drive or it ran from a mounted drive no longer present. No real "right" answer I guess.