Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy

A security operations center (SOC) team is using Microsoft Defender XDR. They have identified a new, highly sophisticated phishing campaign targeting their organization. This campaign uses unique, never-before-seen file hashes for malicious attachments. The SOC needs to quickly block these specific file hashes across all endpoints managed by Microsoft Defender for Endpoint. Which type of Indicator of Compromise (IoC) should they create in Microsoft Defender XDR?

  1. AIP address IoC
  2. BURL/Domain IoC
  3. CFile hash IoC
  4. DCertificate IoC
Show answer & explanation

Correct answer: C. File hash IoC

File hash IoCs are used to block specific malicious files based on their unique hash values. Since the campaign uses 'unique, never-before-seen file hashes', this is the most direct and effective way to block them across endpoints.

Why the other options are wrong

  • A. IP address IoCs block network communication with specific IP addresses, not specific malicious files.
  • B. URL/Domain IoCs block access to specific websites or domains, not specific malicious files.
  • D. Certificate IoCs are used for blocking files signed with specific malicious certificates, not for raw file hashes of attachments.

IoC: File Hash

An Indicator of Compromise (IoC) type in Microsoft Defender XDR that allows security teams to define and enforce blocking or alerting rules based on the unique cryptographic hash of a malicious file.

  • Blocks specific files.
  • Uses SHA1 or SHA256 hashes.
  • Applied across Defender for Endpoint managed devices.

Memory trick: To stop a specific file, you need its unique 'hash' fingerprint.

More Mitigate threats using Microsoft Defender XDR questions