The city's threat-intel program loads only file hashes into Enterprise Security. Actors targeting clerk PCs change hashes daily. What should the SOC do?
Select an answer to reveal the explanation.
Short Explanation
Hashes go stale like milk. Keep the feed — it still catches last night's sample — but pair it with detections that watch how they work, like persistence or signed-binary tricks. A city that only loads SHA-256s will miss tomorrow's rebuild of the same malware.
Full Explanation
Technical indicator intelligence is perishable: daily hash changes defeat a hash-only civic program. The remedy is not to abandon intel or collapse the SOC into one firewall rule or a board briefing. Pair technical feeds with tactical or ATT&CK-oriented detections that match behaviors that survive recompilation. That mix is how Splunk ES stays useful against clerk-PC campaigns that rotate hashes while keeping the same techniques.