A SOC analyst identifies reconnaissance activity originating from an IP address. The activity follows a pattern of brief bursts directed at a small number of targets. An open-source review indicates that the IP has a poor reputation. Perimeter firewall logs show that the inbound traffic was permitted. The destination hosts are high-value assets with EDR agents installed. Which of the following is the best action for the SOC to take to protect against further activity from the source IP?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion