A security analyst detects suspicious fileless activity on an enterprise endpoint, where a legitimate administrative process is spawned to run encoded PowerShell scripts that attempt lateral movement across the internal subnet. The analyst must halt all network communication to and from the compromised host to stop lateral movement, while maintaining active command-and-control connectivity between the endpoint agent and the EDR management console for live forensic investigation. Which of the following Endpoint Detection and Response (EDR) actions should the analyst take?
- Initiate host network isolation through the EDR console agentCevap
- BApply updated egress filtering rules on the perimeter edge firewall
- CRun a traditional signature-based antivirus full system disk scan and quarantine the binary
- DIssue an out-of-band remote hard power-off command to shutdown the physical host
Cevap
Initiate host network isolation through the EDR console agent
The correct action is to initiate host network isolation via the EDR agent console. Host isolation blocks network adapter communication to restrict lateral movement across the enterprise while preserving the EDR agent's control link so SOC analysts can maintain remote command capabilities and capture volatile system memory.
Adım Adım Çözüm
Anahtar Kavram
EDR Host Isolation and Telemetry Preservation