QuestionQ45

Threat Hunting Techniques

A SOC team detected unusual traffic patterns outside normal working hours. Further investigation found that the traffic originated from two specific endpoints that have outbound internet connections. Suspecting possible data exfiltration, the team wants to investigate further based on this hypothesis.

Which two threat indicators support the suspicion of data exfiltration?

Choose two
Explanation

Data exfiltration often includes collecting and compressing files into archives before sending them to an external destination. Requests to file-sharing domains provide a plausible outbound transfer path, and multiple zip commands indicate potential data staging and compression for export.

Community Discussion

No comments yet. Be the first to start the discussion!