A SOC receives a threat-intel report saying a financially motivated ransomware group is targeting healthcare using phishing and encrypted exfiltration. An EDR alert fires for an encoded PowerShell command on an unpatched hospital imaging server. Which concept should the analyst use first to judge alert relevance?
Select an answer to reveal the explanation.
Short Explanation
Think of motivation like a criminal's motive in a detective story—it tells you who is likely to be hit and when. You want to know whether ransomware chasing quick money fits a hospital imaging server, not just whether an IP looks scary. The trap is chasing shiny indicators while ignoring the reason behind the attack.
Full Explanation
Threat actor motivation is a predictive lens for relevance: it links why an adversary operates to what it likely targets, which techniques it uses, and when it is likely to act. A financially motivated ransomware group is more likely to pursue quick extortion against exposed operational systems, using phishing, credential access, and encrypted exfiltration, so motivation helps an analyst decide whether observed behavior is plausibly related rather than background noise. Source type and publication freshness matter for confidence and timeliness, but they do not by themselves indicate whether observed behavior fits the adversary’s goals. Geography and victim industry add context, yet they are weaker predictors than motivation because actors can operate across borders and industries. Matching only to a named malware family is too narrow, since groups rotate tooling and infrastructure while often preserving their core objective and campaign patterns. Exam caveat: motivation is not evidence of compromise; it should be combined with indicators, tactics, techniques, and asset exposure. Operational check: map the alert to the reported motivation and MITRE ATT&CK techniques before prioritizing escalation.