Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security operations center (SOC) is leveraging Microsoft Defender XDR. They have identified a sophisticated threat actor who is known to use specific command-and-control (C2) domains that are not yet blacklisted by standard threat intelligence feeds. The SOC needs to create a custom indicator that will immediately block all network connections to these identified C2 domains across all managed endpoints. Which type of custom indicator should they create in Microsoft Defender XDR?

  1. AIP address
  2. BCertificate
  3. CFile hash
  4. DURL/Domain
Show answer & explanation

Correct answer: D. URL/Domain

To block network connections to specific command-and-control (C2) domains, a custom indicator of compromise (IoC) of type 'URL/Domain' should be created in Microsoft Defender XDR. This allows the security team to define a list of malicious domains that Defender will block access to on endpoints.

Why the other options are wrong

  • A. IP address indicators can block access to specific IPs, but domains are more effective for C2 as IPs can change.
  • B. Certificate indicators are used to identify and block software signed with specific malicious certificates.
  • C. File hash indicators are used to block or audit specific malicious files, not network connections to domains.

IoC: URL/Domain

A type of custom indicator of compromise in Microsoft Defender XDR used to define malicious URLs or domains that should be blocked, allowed, or audited on managed devices.

  • Blocks access to specified malicious web addresses.
  • Effective for disrupting command-and-control (C2) communications.
  • Can be set with different actions: Allow, Audit, Block, Alert.

Memory trick: IoCs are your custom blocklist, telling Defender what to stop.

More Mitigate threats using Microsoft Defender XDR questions