An engineer received a report of a suspicious email from an employee. The employee had already opened the attachment, which was an empty Word document. The engineer cannot identify any clear signs of compromise but while reviewing running processes, observes that PowerShell.exe was spawned by cmd.exe with a grandparent winword.exe process. What is the recommended action the engineer should take?
Refer to the exhibit.
Which two actions should be taken based on the intelligence information? (Choose two.)
Which scripts will search a log file for the IP address of and create an output file named parsed_host.log while printing results to the console?