Quiz 3 Question 19 of 20

A Suricata rule fires on a connection: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:'ET TROJAN Possible Cobalt Strike Beacon'; content:'|00 00 00 00|'; offset:4; depth:4;). The alert shows the source host is the CFO's laptop. What is the correct next analytical step?

Select an answer to reveal the explanation.

Motivation