QuestionQ30

Threat Hunting Processes

Refer to the exhibit.

Question Image

A threat analyst examines an OSINT platform used to share and request indicators of compromise associated with various malware strains. The analyst must obtain threat intelligence from the platform about the indicators of compromise for future intelligence-driven threat hunting.

Which action should the analyst take to achieve this goal?

Explanation

MalwareBazaar provides API queries to retrieve malware-sample and indicator data associated with a specified tag or malware signature, and those queries use HTTP POST form data. Importing the current dataset returned by that API enables subsequent SIEM or threat-hunting use.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!