QuestionQ38

Incident response

You have identified and isolated a new malware sample installed by an advanced threat group that you believe was created specifically for an attack against your organization. You want to analyze this malware quickly and efficiently to obtain IOCs without alerting the threat group. What should you do?

  • A Search for the threat group in Google Threat Intelligence.
  • B Upload the malware to Google Threat Intelligence by using VirusTotal.
  • C Upload the malware to Google Threat Intelligence by using Private Scanning.
  • D Calculate the file checksum for the malware, and search for the checksum in GoogleThreat Intelligence by using VirusTotal.
Explanation

Google Threat Intelligence Private Scanning supports deep analysis and sandbox detonation of a submitted file while keeping the submission private rather than sharing it immediately with the broader community. This enables IOC discovery for a suspected targeted sample without publicly exposing the malware or campaign.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!