This week was more centered around Incident Response, which isn’t normally in my wheelhouse, so I Was excited to maybe learn a few tricks. Part 1 The first part of the question was asking what package was installed by the attacker. Considering some of the previous questions, I immediately went to a…