Threat intelligence reports a malware family with a unique static file pattern. The SOC has historical endpoint file store samples and wants to hunt for prior presence without blocking or quarantining anything. Which action best fits the request?
Select an answer to reveal the explanation.
Short Explanation
Think of YARA like a metal detector for files: you sweep the pile for known shapes without pulling anything out. If the ask is hunting, you scan historical stores for static patterns; quarantine, isolation, or alerting are response moves, not the hunt.
Full Explanation
YARA is designed to search file content with rules built from static indicators such as byte strings, regular expressions, or PE attributes. In threat hunting, the analyst applies those rules to a collected corpus—endpoint file stores, malware sample archives, or disk image extracts—to find historical traces of a family. The action is intentionally investigative: it identifies candidate files for later triage without automatically altering the environment. An EDR containment policy that isolates hosts when a pattern is observed is a response control, because it changes the endpoint state after a match. A SIEM correlation rule that alerts when matching file names appear in logs is a detection use case, and file names are weaker indicators than YARA content patterns. Sandbox detonation analyzes behavior after a sample has already been selected; it does not sweep a broad file store for prior presence. Exam caveat: YARA can support both hunting and detection, but the requested action determines the answer; when the task is historical discovery, choose scanning. Operational check: run the YARA rule against the read-only file-store export, log the matched paths and hashes, then send only the suspicious matches to malware analysis or endpoint response.