← Host & Memory Hunting at Scale
Module Quiz
10 questions · Pass at 80%
Question 1 of 10
A fleet hunt finds 'OneDriveStandaloneUpdater.exe' running from C:\Users\jsmith\AppData\Roaming\ on 1 host, while 1,847 other hosts run the same process name from C:\Program Files\Microsoft OneDrive\. The binary in AppData has the same SHA256 as the legitimate OneDrive binary. What attack technique does this most likely represent?