During containment of a phishing incident, EDR confirms a suspicious executable ran on one workstation. You obtain its SHA-256 hash. To quickly identify every other endpoint that executed the same sample, which action should you take?
Select an answer to reveal the explanation.
Short Explanation
Think of the SHA-256 hash as the malware's fingerprint. You want every host that ran the same executable, so you ask EDR to search process telemetry for that hash across the fleet. Chasing C2 traffic or proxy logs may help, but it won't prove another endpoint executed the same file.
Full Explanation
File-hash pivoting uses a cryptographic identifier for a specific binary to measure blast radius. EDR process-creation telemetry often stores the executable's SHA-256, path, parent process, and host ID. Searching that field across monitored endpoints reveals every host that executed the same sample, even if filenames changed. This is a scoping step, not a detection-tuning step. Network pivoting based on command-and-control destinations can show additional infected hosts, but it depends on beaconing, egress logging, and destination reliability, so it can miss hosts that never reached the network. YARA matching is useful for finding similar artifacts, yet applying it to proxy logs or metadata does not confirm process execution and may return unrelated downloads. Vulnerability scan data can identify systems with a shared software fingerprint or missing patches, but that indicates exposure, not actual execution of the malicious file. Exam caveat: when a question gives a known hash and asks for scope, choose the telemetry source that directly proves execution, usually EDR process events. Operational check: submit the SHA-256 to the EDR search console, filter to process-start events, and export host, user, timestamp, and parent-process columns for every match.