QuestionQ10

Threat Hunting Techniques

A SOC team must prepare for a new phishing campaign that deceives users into clicking a malicious URL to download a file. When that file runs, it creates a Windows process that harvests user credentials. The team must configure the SIEM tool to generate an alert when a suspicious process is detected.

Which two rules must the team create in the SIEM tool?

Choose two
Explanation

Credential-stealing malware can masquerade by using the names of common legitimate processes or by executing from nonstandard paths. Monitoring process-name anomalies and unusual execution locations helps identify malicious processes that attempt to blend in with normal Windows activity. MITRE ATT&CK identifies manipulation of a resource’s name or location as masquerading and includes detection analytics based on suspicious process names and paths.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!