CloudOps Training Hub / Security Investigation
WINDOWS SERVERPLESKCLOUDOPS

Security Investigation

Investigate suspicious processes and scheduled activity without destroying evidence.

Unknown process using 90% CPU

Process name
File location
Publisher/signature
Parent process
Service / Task
Network activity
AV/EDR + Logs
Do not kill it first. The process could be Windows, IIS, Plesk, an application, backup, monitoring or another legitimate component.

Scheduled Tasks

taskschd.msc