@gjacobse said in I can't even:
Oh for FFS -
An alert has been fired on local host DOMAIN\COMPUTER regarding user myuser. A suspicious powershell script has been found in C:\Users\myuser\Desktop\Teams_ODfB.ps1. Please let us know if this is legitimate.
This is the script
Start-Process -File "$($env:USERProfile)\AppData\Local\Microsoft\Teams\Update.exe" -ArgumentList '--processStart "Teams.exe"' Start-Process -FilePath "$env:LOCALAPPDATA\Microsoft\OneDrive\OneDrive.exe" -ArgumentList "/background"
Which only starts Teams and ODfB.... Like.. JFC -
Hey we don't know what it does we're just script kiddies out here, tell us if this is kosher, thanks!