An endpoint, inside an organization, is infected with known malware. The malware attempts to make a command and control connection to a C&C server via the destination IP address.
Which mechanism prevent this connection from succeeding?
DNS Sinkholing seems like the obvious choice here. It redirects the malware's attempt to connect to the C&C server to a benign destination, effectively blocking the connection.
Glennis
4 days agoSylvia
8 days agoJovita
10 days agoSheridan
12 days ago