Hello everyone,
I am trying to find out what search string I could use to see what file was created after a malicious file was ran. The malicious file is called template.pdf, but I can't seem to figure out what search string to use to see what file was created after the user opened it.
Are you logging file creations? If so, how?