An analyst notices PowerShell commands with Base64-encoded arguments in endpoint logs. What is the MOST appropriate immediate action?
-
A
Delete the PowerShell executable from the host
-
B
Isolate the host and escalate for deeper investigation
-
C
Whitelist the encoded command to suppress future alerts
-
D
Restart the affected system