nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #70

During an incident response engagement, a forensic investigator discovers a persistent threat actor using a custom command-and- control (C2) protocol over port 53 (DNS). The existing SIEM logs show…

The correct answer is B. WildFire for malware detonation and real-time signature generation, coupled with extensive Unit. WildFire is excellent for understanding the technical aspects of malware, including its C2 communication. However, for a holistic view of the adversary's TTPs, motivations, and broader campaigns, Unit 42's detailed threat research, adversary playbooks, and intelligence reports…

Advanced Threat Intelligence and Incident Response

Question

During an incident response engagement, a forensic investigator discovers a persistent threat actor using a custom command-and- control (C2) protocol over port 53 (DNS). The existing SIEM logs show only generic DNS queries. To gain a comprehensive understanding of the adversary's TTPs (Tactics, Techniques, and Procedures), including their C2 infrastructure, exploit development, and motivation, and to proactively block future attacks, which combination of resources would be most beneficial?

Options

  • AVirusTotal for file hash lookups and open-source intelligence blogs for general threat trends.
  • BWildFire for malware detonation and real-time signature generation, coupled with extensive Unit
  • CPassive DNS reconnaissance and WHOIS lookups for the C2 domains.
  • DEmploying a commercial Endpoint Detection and Response (EDR) solution without integrating
  • EDeep packet inspection of all network traffic and manual reverse engineering of all suspicious

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    80% (16)
  • D
    10% (2)
  • E
    5% (1)

Explanation

WildFire is excellent for understanding the technical aspects of malware, including its C2 communication. However, for a holistic view of the adversary's TTPs, motivations, and broader campaigns, Unit 42's detailed threat research, adversary playbooks, and intelligence reports are invaluable. Unit 42 focuses on in-depth analysis of threat actors, their campaigns, and the broader threat landscape, providing strategic and tactical intelligence that complements WildFire's technical output. This combination allows for both technical understanding of the attack and strategic intelligence on the adversary.

Topics

#DNS C2#Unit 42 threat intelligence#WildFire#APT TTP analysis

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice