Which memory forensics artifact can reveal the full command-line arguments used to launch a malicious process, even after the process has terminated?
-
A
Windows Event ID 4688 (process creation) in Security logs
-
B
The process's PEB (Process Environment Block) in RAM
-
C
File system prefetch records (.pf files)
-
D
Registry Run keys