QuestionQ40

Threat Hunting Techniques

Refer to the exhibit.

Question Image

A security analyst at a company conducts a forensic analysis of an endpoint after an endpoint detection and response solution flags it as infected. Following additional investigation, the analyst determines that a registry value was changed.

According to the MITRE ATT&CK framework, which technique did the malware employ?

Explanation

Changing the Office VBAWarnings registry value weakens macro security warnings, helping malicious VBA execute without the normal protective prompt. MITRE ATT&CK identifies registry modification used to enable Office macros or impair protections as behavior associated with the Defense Evasion tactic.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!