An ICS threat hunter is following a structured, hypothesis-driven methodology. After reviewing recent threat intelligence about adversaries targeting their industry, what is the most logical first step for the hunter to take?
-
A
Immediately deploy new firewall rules based on the intelligence report's IOCs.
-
B
Begin a full packet capture on all network segments to gather new data.
-
C
Formulate a specific, testable question about potential adversary activity in their environment.
-
D
Scan all HMIs and engineering workstations for the malware hashes mentioned in the report.