QuestionQ23

Threat Hunting Techniques

The SOC team receives threat intelligence about a new ransomware variant spreading across businesses. After validating existing suspicious-email use cases, the team creates a new use case using known indicators of compromise for that specific ransomware variant. The focus is on detecting the ransomware attack during its execution phase.

What should be monitored?

Explanation

Ransomware encryption commonly causes a rapid, high-volume burst of file writes, rewrites, renames, or other modifications as it encrypts users’ files. Monitoring unusually large numbers of file modifications can therefore identify the ransomware payload while it is operating. MITRE ATT&CK detection guidance for Data Encrypted for Impact likewise identifies high-frequency file-write activity and file-modification telemetry as detection signals.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!