QuestionQ4

Threat Hunting Outcomes

A security analyst receives an alert that host A, with the IP address 192.168.5.39, has had a new browser extension installed. While investigating SIEM tool logs, the analyst finds that host A made continuous TCP connections to 1.25.241.8 over TCP port 80. The IP address 1.25.241.8 is categorized as a C2 server.

Which action should the analyst take to mitigate similar connections going forward?

Explanation

A browser extension deny list prevents installation or use of known-unapproved extensions that can establish command-and-control communications. This addresses the likely source of the continuous C2 connections and reduces recurrence of similar browser-extension-based activity.

Community Discussion

No comments yet. Be the first to start the discussion!