Your SIEM alerts on a suspicious PowerShell execution event linked to file hash A1B2C3D4. The hash is confirmed as malicious malware. To identify additional command-and-control infrastructure associated with this specific sample, which action should you take?
Select an answer to reveal the explanation.
Short Explanation
Think of a file hash like a fingerprint: once you confirm it, you ask your intel source where else that fingerprint shows up. That pivot reveals related C2 domains or IPs you can hunt for next. Don't stop at blocking the one IP you already have — that's containment, not expansion.
Full Explanation
Pivoting is a core threat-hunting technique where an analyst takes a confirmed indicator of compromise, such as a file hash, and uses it to discover related malicious infrastructure. Threat intelligence platforms aggregate feeds and historical observations, so querying the hash can return associated command-and-control domains, IP addresses, or peer samples. This expands the investigation from one endpoint event to broader campaign awareness and supports proactive hunting for infrastructure not yet observed in the environment. Blocking the observed source IP is containment for the current alert but does not identify additional infrastructure; it assumes the single address is the only control point, which is uncommon for modern malware families. Reimaging the endpoint is remediation, not intelligence expansion, and can destroy forensic evidence needed to understand the full scope of the compromise. Submitting the file to a sandbox for static analysis helps reveal behavior, persistence, or payloads, but it does not correlate the hash to external attacker infrastructure. Exam caveat: Pivot quality depends on the trusted, current threat intelligence source and the confidence of the original indicator. Operational check: Enrich the hash in your SIEM or SOAR, then hunt for returned C2 indicators across proxy logs, DNS logs, and firewall telemetry.