Quiz 3 Question 1 of 20

An analyst suspects a specific ransomware variant is active on a compromised endpoint. The EDR agent is offline, but the analyst has remote access to the file system and wants to identify infected files by matching known binary signatures against on-disk artifacts. Which tool is most appropriate for this task?

Select an answer to reveal the explanation.

Motivation