After ransomware-like activity, a SOC analyst has forensic disk images from several workstations and a known malware string from a sample. The analyst needs to locate every file containing that string across all images before deciding containment. Which incident response technique should be used first?
Select an answer to reveal the explanation.
Short Explanation
Think of YARA like a metal detector for files: you set the pattern, then sweep the whole image. The trap is hunting for alerts that already fired; here you need to find hidden files by content. That is why scanning disk images with a YARA rule is the move.
Full Explanation
YARA is a file-content matching engine, so it is well suited to hunting a known malware string, byte pattern, or signature across acquired endpoint images when no alert has already identified the artifact. The analyst supplies a rule with a characteristic string or hex pattern, then applies it to files within mounted forensic images; hits indicate candidate files for deeper malware analysis. This is proactive hunting because it starts from a hypothesis about file content rather than from a security event that already triggered a control. Triage of EDR alerts is not the best choice here because it only reviews detections the endpoint agent already generated, which misses dormant, deleted, or unsigned files that never caused an alert. Creating a SIEM correlation rule also depends on log events, so it cannot inspect raw file bytes inside offline disk images. Checking NetFlow for the string is wrong because network traffic metadata and payloads may show C2 behavior, but flow records do not provide persistent endpoint file contents for systematic content matching. Exam caveat: distinguish detection triage from threat hunting; YARA hunts files, not alerts. Operational check: mount each endpoint image read-only, run the YARA rule against all files, and record rule version, hash, and matched paths for chain of custody.