An EDR alert fires for a malware sample using PowerShell to create a scheduled task and beacon to a new C2. The SOC blocks the file hash and destination IP. Two days later, the same campaign appears with a different hash but similar command-line arguments and persistence. Which response is most durable?
Select an answer to reveal the explanation.
Short Explanation
Think of a file hash like a license plate: it catches one car, not the same driver stealing another car. You need to hunt for how the driver drives — persistence, command lines, lateral movement — so variants don’t slip past. That’s why TTP-based response outlasts IOC-only blocking.
Full Explanation
Indicators of compromise such as hashes, IPs, and domains are precise but brittle: when malware is repacked or a C2 endpoint changes, the exact value changes while the behavior may remain. TTP hunting focuses on adversary methods—scheduled-task persistence, encoded PowerShell, unusual parent-child process relationships, or repeated beacon intervals—so detection and response can cover many samples derived from the same campaign. In a hybrid SOC, this means pivoting from EDR telemetry to SIEM/SOAR correlation and threat-hunting queries instead of only updating blocklists. Relying on additional hash blocks is reactive and creates an arms race because each new build can produce a new hash while retaining the same actions. Requiring full reverse-engineering before detection updates delays containment and ignores useful behavioral telemetry that already exists. Disabling alerts to reduce noise is unsafe because it suppresses the very signal that reveals the variant and allows the adversary to continue operating. Exam caveat: when a question asks for durability after IOC churn, choose response anchored in behavior and TTPs rather than static indicator expansion. Operational check: create a hunting rule for scheduled-task creation by PowerShell with encoded commands and correlate it with outbound beaconing before blocking the next hash.