Operational intelligence says a ransomware affiliate is targeting municipal Microsoft 365 this week. What should the city SOC analyst do first?
Select an answer to reveal the explanation.
Short Explanation
A this-week campaign is a fire drill, not a ten-year master plan. Hunt forwarding rules and consent grants in M365 data now, while the window is open. Architecture can wait; printer hashes and turning ES off do not answer the bulletin.
Full Explanation
Operational intelligence should become a time-bounded hunt aligned to the campaign's likely path. For municipal Microsoft 365 ransomware affiliates, mailbox-forwarding and consent-grant logs are the civic identity and email data that can show staging this week. Rewriting a three-year architecture plan is strategic/architect work, printer hashes are irrelevant technical noise, and disabling ES removes the analyst's workspace. Defense Analysts convert the bulletin into searches, not into a program redesign overnight.