An analyst receives a threat intelligence report describing a new APT group using a specific YARA signature pattern in their custom implant. The organization has a SIEM with endpoint telemetry. Which action most effectively operationalizes this intelligence?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because operationalizing threat intelligence means converting indicators (YARA signatures) into active detections; retrospective hunting may reveal past compromise, and real-time alerting catches future activity. A is wrong because filing without action wastes actionable intelligence.
Full explanation below image
Full Explanation
B is correct because operationalizing threat intelligence means converting indicators (YARA signatures) into active detections; retrospective hunting may reveal past compromise, and real-time alerting catches future activity. A is wrong because filing without action wastes actionable intelligence. C is wrong because legal review is unrelated to technical operationalization. D is wrong because geoblocking by country is an extremely blunt tool that the APT group can trivially bypass with infrastructure in other countries.