Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security operations center (SOC) is leveraging Microsoft Defender XDR. They have identified a sophisticated threat actor who is known to use specific command-and-control (C2) domains that are not yet blacklisted by standard threat intelligence feeds. The SOC needs to create a custom indicator that will immediately block all network connections to these identified C2 domains across all managed endpoints. Which type of custom indicator should they create in Microsoft Defender XDR?
- AIP address
- BCertificate
- CFile hash
- DURL/Domain
Show answer & explanationAnswer & explanation
Correct answer: D. URL/Domain
To block network connections to specific command-and-control (C2) domains, a custom indicator of compromise (IoC) of type 'URL/Domain' should be created in Microsoft Defender XDR. This allows the security team to define a list of malicious domains that Defender will block access to on endpoints.
Why the other options are wrong
- A. IP address indicators can block access to specific IPs, but domains are more effective for C2 as IPs can change.
- B. Certificate indicators are used to identify and block software signed with specific malicious certificates.
- C. File hash indicators are used to block or audit specific malicious files, not network connections to domains.
IoC: URL/Domain
A type of custom indicator of compromise in Microsoft Defender XDR used to define malicious URLs or domains that should be blocked, allowed, or audited on managed devices.
- Blocks access to specified malicious web addresses.
- Effective for disrupting command-and-control (C2) communications.
- Can be set with different actions: Allow, Audit, Block, Alert.
Memory trick: IoCs are your custom blocklist, telling Defender what to stop.