A security analyst has received an incident case regarding malware spreading out of control on a customer's network. The analyst is unsure how to respond. The configured EDR has automatically obtained a sample of the malware and its signature. Which of the following should the analyst perform next to determine the type of malware, based on its telemetry?
The signature of the malware is a unique identifier that can be used to compare it with known malware samples and their behaviors. Open-source threat intelligence sources provide information on various types of malware, their indicators of compromise, and their mitigation strategies. By cross-referencing the signature with these sources, the analyst can determine the type of malware and its telemetry. The other options are not relevant for this purpose: configuring the EDR to perform a full scan may not provide additional information on the malware type; transferring the malware to a sandbox environment may expose the analyst to further risks; logging in to the affected systems and running netstat may not reveal the malware activity.
Izetta
8 months agoBerry
8 months agoShizue
9 months agoIlene
9 months agoJaney
10 months agoPete
10 months agoDarrin
10 months agoFrancoise
11 months agoCarey
11 months agoShawna
11 months agoRyan
11 months agoCelestine
11 months agoAndrew
11 months agoRaul
12 months agoLeonora
12 months agoMargo
1 year agoDana
9 months agoLeota
9 months agoCarline
9 months agoDevorah
10 months agoAmber
1 year agoSage
12 months agoJovita
1 year agoRomana
12 months agoJosephine
12 months agoReita
12 months ago