During a live response, an analyst runs 'netstat -ano' on a compromised host and finds an established connection to an external IP on port 443. What is the FIRST action the analyst should take?
-
A
Immediately terminate the process holding the connection
-
B
Document the connection details including PID, remote IP, and timestamp before taking any action
-
C
Block the external IP at the firewall
-
D
Reboot the system to terminate all active connections