Session length

1 / 20

An APT actor is suspected with IOCs including a SHA256 of a malicious DLL, a C2 domain, and rundll32.exe spawning powershell.exe with obfuscated arguments. If Sysmon data is inconsistent and process hashes are unreliable, which approach is best?

Write a multi-event YARA-L detection rule that correlates process relationship and hash, then run a retrohunt.

Build a reference list containing hash and domain and link to a high-frequency rule.

When signals are unreliable or incomplete, detection should hinge on stable indicators and scalable rules that can catch activity across multiple data sources. In this scenario, anchoring detections to a reference list of known IOCs (the DLL’s SHA256 and the C2 domain) and tying those to a high-frequency rule gives broad, consistent coverage without relying on brittle process hashes or perfect Sysmon data.

Why this approach fits best: a reference list provides a single, centralized source of truth for the IOCs you care about. By linking those indicators to a rule that runs across all telemetry streams (endpoint, network, cloud logs, etc.), you can surface detections whenever any event touches those IOCs, even if process hashes are inconsistent or Sysmon data is incomplete. This method also scales well: as you discover more IOCs, you add them to the reference list and the high-frequency rule automatically benefits from the expanded coverage. It effectively bridges multiple data sources—file creation, network connections to the C2 domain, and script activity—without depending on any single unreliable signal like process relationships or exact hash matches in a noisy environment.

The other options rely more on brittle or narrow signals: correlating multiple events with YARA-L requires reliable event data and relationships to be meaningful; a retrohunt focuses on past data and may miss present activity when data is inconsistent; a single-event hash rule is fragile if the hash changes or if telemetry doesn’t capture the hash consistently; and focusing only on rundll32.exe usage misses the broader context of the C2 domain and the malicious DLL.

Single-event rule based on file hash and run against telemetry.

Use SecOps search to identify recent rundll32.exe uses and tag assets.

Next question

Find the option that is right for you!

All options are one-time payments.

$12.50

30 day premium pass

All the basics to get you started

  • Ad-free experience
  • View your previous attempt history
  • Mobile app access
  • In-depth explanations
  • 30 day premium pass access
$30.00 $87.50 usd

6 month DELUXE pass (most popular)

Everything with the 30 day premium pass FOR 6 MONTHS! & the ultimate digital PDF study guide (BONUS)

  • Everything included in the premium pass
  • $87.50 usd value for $30.00! You save $57.50!
  • + Access to the ultimate digital PDF study guide
  • + 6 months of premium pass access
  • + Priority support
$12.50 $18.99

Ultimate digital PDF study guide

For those that prefer a more traditional form of learning

  • Available for instant download
  • Available offline
  • Hundreds of practice multiple choice questions
  • Comprehensive content
  • Detailed explanations
Image Description
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy