Cisco CyberOps Associate (CBROPS) 200-201 flashcards
179 free flashcards. Tap a card to flip it.
Signature-based Detection
Flip cardA method of intrusion detection that identifies threats by comparing observed data (e.g., network traffic, file hashes) against a database of known attack patterns or 'signatures'.
- Relies on a database of known attack patterns.
- Effective against previously identified threats.
- High accuracy for known attacks, low false positives.
- Ineffective against new or zero-day attacks.
Memory trick: IDS methods are like detectives: some look for exact fingerprints (signatures), others for unusual behavior (anomalies).
Security Architecture & Design
Flip cardA proactive security program element focused on integrating security considerations into the initial planning, design, and implementation phases of systems, applications, and infrastructure.
- Aims to build security in from the ground up ('Secure by Design').
- Involves defining security requirements, choosing appropriate controls, and creating secure blueprints.
- Reduces the cost and effort of fixing security vulnerabilities later.
Memory trick: Design it Right, Secure it Tight.
Data Classification
Flip cardThe process of organizing data into categories based on its sensitivity and impact if compromised, to apply appropriate security controls.
- Helps determine necessary security measures.
- Typically includes categories like Public, Internal, Confidential, Restricted.
- Impact assessment is crucial for classification.
Memory trick: Public parks are open, but Restricted areas are guarded.
CVE (Common Vulnerabilities and Exposures)
Flip cardA list of publicly disclosed cybersecurity vulnerabilities, each assigned a unique identifier (CVE ID) to facilitate data sharing and enable automation.
- Standardizes vulnerability identification.
- Maintained by MITRE Corporation.
- Used by security vendors and researchers worldwide.
Memory trick: CVE IDs give vulnerabilities a name.
Principle of Least Functionality
Flip cardA security principle that dictates that systems and applications should be configured to provide only the essential capabilities required for their intended purpose, disabling or removing all unnecessary services, applications, and functions.
- Reduces the attack surface.
- Minimizes potential vulnerabilities.
- Applies to operating systems, applications, and network devices.
- Often involves removing default configurations and unnecessary software.
Memory trick: Security principles are rules for strong defenses; least functionality means only what's needed.
Digital Signature
Flip cardA mathematical scheme for demonstrating the authenticity of digital messages or documents. A valid digital signature gives a recipient reason to believe that the message was created by a known sender (authentication), that the sender cannot deny having sent the message (non-repudiation), and that the message was not altered in transit (integrity).
- Uses asymmetric cryptography (public/private key pairs).
- Provides data integrity, data origin authentication, and non-repudiation.
- Often involves hashing the message first, then encrypting the hash with the sender's private key.
- Verifier uses sender's public key to decrypt the hash and compare it to a newly computed hash of the message.
Memory trick: Crypto tools secure data; signatures prove who sent it and that it's untouched.
Black-Box Penetration Test
Flip cardA type of penetration test where the tester has no prior knowledge of the target system's internal structure or source code, simulating an external attacker.
- Mimics a real-world external attacker.
- Focuses on identifying vulnerabilities visible from the outside.
- Requires extensive reconnaissance by the tester.
Memory trick: Black-box is 'Blind' testing, like an attacker from outside.
Brute-force Attack
Flip cardA brute-force attack is a trial-and-error method used to obtain information such as a user password or personal identification number (PIN). It involves systematically checking all possible passwords until the correct one is found.
- Characterized by numerous failed login attempts.
- Can target various services (SSH, RDP, web logins).
- Often originates from multiple IPs to evade rate limiting.
- Can be mitigated by strong passwords, account lockout policies, and multi-factor authentication.
Memory trick: Authentication attacks are like trying to pick a lock, some are quick guesses, others are systematic.
Security Monitoring
Flip cardThe continuous process of collecting, analyzing, and reviewing data from various sources (e.g., logs, network traffic) to detect and respond to security incidents and anomalies.
- Proactive and reactive threat detection.
- Utilizes tools like SIEM, IDS/IPS, EDR.
- Essential for maintaining situational awareness.
Memory trick: Monitor the gates, manage the risks, train the guards, recover from disasters.
SYN Flood Attack
Flip cardA type of Denial of Service (DoS) attack that exploits the TCP three-way handshake. The attacker sends a high volume of SYN requests to a target server but does not respond to the server's SYN-ACKs, leaving many half-open connections that exhaust the server's resources and prevent legitimate connections.
- Targets TCP services.
- Exploits the three-way handshake.
- Sends SYN, never ACK.
- Fills server's connection table (backlog).
Memory trick: SYN Flood is like knocking on a door and running away, over and over, until no one can get in.
Network Intrusion Prevention System (IPS)
Flip cardA network security appliance that monitors network traffic for malicious activity, logs information about it, attempts to block it, and reports it.
- Active prevention of network attacks.
- Operates in-line with network traffic.
- Can block known attack signatures and anomalies.
Memory trick: IDS/IPS are the network guards, watching and blocking bad traffic.
Persistence Mechanisms
Flip cardTechniques used by attackers to maintain access to a compromised system across reboots, loss of network connectivity, or credential changes.
- Ensures malware or attacker tools restart automatically.
- Common methods include registry run keys, startup folders, scheduled tasks, and services.
- Crucial for long-term compromise and covert operations.
Memory trick: After the initial breach, the attacker wants to stay, like a persistent guest.
Threat Intelligence Integration
Flip cardThe practice of incorporating actionable information about current and emerging cyber threats into an organization's security operations, including vulnerability management, to make more informed decisions.
- Provides context on attacker TTPs.
- Aids in prioritizing vulnerabilities based on real-world risk.
- Enhances proactive defense strategies.
Memory trick: Intel makes the most critical vulnerabilities visible.
Packet Capture & Decryption
Flip cardThe process of intercepting and recording network traffic (packet capture) and subsequently converting encrypted traffic back into readable plaintext (decryption) to analyze its contents.
- Essential for deep inspection of network payload data.
- Requires access to encryption keys/certificates for encrypted traffic.
- Tools like Wireshark are used for capture and analysis.
Memory trick: To know what's in the box, you need the key, or at least a peek!
Botnet (Bot) Characteristics
Flip cardA botnet is a network of compromised computers (bots) controlled by a threat actor (bot-herder) via a command and control (C2) server. Bots often run with low privileges and communicate covertly with the C2.
- Performs C2 communication (often via HTTP, DNS, or custom protocols).
- Often runs as a low-privilege user.
- Used for DDoS, spam, data theft, and other malicious activities.
- May use random or high-numbered ports to evade detection.
Memory trick: A robot calling home from a hidden phone.
Command and Control (C2)
Flip cardA communication channel used by attackers to control compromised systems (bots or agents) within a target network. It enables attackers to issue commands, exfiltrate data, and maintain persistent access.
- Establishes persistent communication with compromised hosts.
- Uses various protocols and ports, often non-standard ones, to evade detection.
- Allows attackers to remotely manage and direct malicious activities.
- Often involves external communication to attacker-controlled infrastructure.
Memory trick: Bots Chatting Remotely
Data Sovereignty
Flip cardThe concept that digital data is subject to the laws and regulations of the country in which it is stored or processed.
- Crucial for compliance with international data protection laws (e.g., GDPR).
- Influences cloud service provider selection and data residency requirements.
- Can impact data access by foreign governments.
Memory trick: GDPR's Sovereignty: Data Stays Home, Legally.
Full Disk Encryption (FDE)
Flip cardA security feature that encrypts all data on a hard drive or storage device, protecting it from unauthorized access if the device is lost, stolen, or accessed by an unauthorized party.
- Encrypts the entire storage volume, including operating system and user data.
- Data is unreadable without the correct decryption key or password.
- Protects 'data at rest'.
- Commonly implemented on laptops, desktops, and mobile devices.
Memory trick: Endpoint security guards the device itself, like FDE locking all its data.
SSH (Secure Shell)
Flip cardA cryptographic network protocol for operating network services securely over an unsecured network. It is typically used for remote command-line login and remote command execution, but also supports tunneling, port forwarding, and file transfers.
- Uses TCP port 22 by default.
- Provides strong authentication and encrypted communication.
- Commonly used for remote administration.
- Frequently abused by attackers for C2 channels or data exfiltration due to its encrypted nature.
Memory trick: Ports are digital doors; knowing their numbers helps identify what's coming and going.
Log Parsing and Normalization
Flip cardThe process by which a SIEM system extracts relevant data fields from raw, unstructured log messages and transforms them into a standardized, structured format for easier analysis and correlation.
- Essential for making heterogeneous log data usable.
- Involves identifying timestamps, source/destination IPs, event types, etc.
- Enables cross-source correlation and consistent querying.
Memory trick: Before you can read a book, you need to know the language and grammar.
Non-repudiation
Flip cardA security principle that guarantees that the sender of a message or the performer of an action cannot later deny having sent the message or performed the action.
- Often achieved using digital signatures and cryptographic hashing.
- Provides proof of origin and integrity.
- Crucial in legal and financial transactions.
Memory trick: CIA + AAN (Authentication, Authorization, Non-repudiation)
Credential Stuffing
Flip cardAn attack where an attacker takes a list of compromised username-password pairs, often obtained from a data breach on one service, and attempts to use them to log into a large number of other, unrelated online services.
- Relies on users reusing passwords across multiple sites.
- Automated using bots.
- Often follows a large data breach.
Memory trick: Remember, 'stuffing' implies filling many login forms with stolen credentials.
Cross-Site Scripting (XSS)
Flip cardA type of security vulnerability typically found in web applications that enables attackers to inject client-side scripts into web pages viewed by other users.
- Targets web applications.
- Involves injecting client-side scripts (e.g., JavaScript).
- Affects other users viewing the compromised content.
- Can lead to session hijacking, defacement, or malware delivery.
Memory trick: Web attacks target the browser and server, like XSS injecting scripts to cross sites.
SQL Injection Signatures
Flip cardSQL injection signatures are specific keywords, functions, or patterns found within attacker-crafted SQL queries that indicate an attempt to exploit database vulnerabilities.
- Common keywords: 'UNION SELECT', 'OR 1=1', 'DROP TABLE'.
- Functions for enumeration: '@@version', 'user()', 'database()'.
- Functions for timing attacks: 'SLEEP()', 'pg_sleep()'.
- Often seen in web application logs targeting input fields.
Memory trick: Web app attacks are like trying to break into a house through its windows, some target specific flaws.
Principle of Least Privilege
Flip cardA security principle requiring that a user or process be given only the minimum necessary authorization to perform its function.
- Reduces the attack surface.
- Limits the damage from compromised accounts.
- Requires regular review of access rights.
Memory trick: Least Privilege: Only give them the keys they need, no extra.
Principle of Least Privilege (PoLP)
Flip cardA security principle requiring that users, programs, or processes be granted only the essential access rights or permissions needed to perform their assigned functions, and no more. This minimizes the potential damage from errors, compromises, or malicious actions.
- Grants minimum necessary access.
- Reduces attack surface and impact of compromise.
- Applies to users, applications, and systems.
Memory trick: Only give the key to the specific room they need, not the whole building.
Protocol Mismatching/Port Masquerading
Flip cardA technique where attackers use a well-known port (e.g., 80, 443) for a protocol other than its standard, often to bypass firewall rules and network monitoring.
- Leverages trust in common ports to hide malicious traffic.
- Requires deep packet inspection (DPI) to detect.
- Often used for C2 communication or data exfiltration.
Memory trick: Attackers hide in plain sight, changing their clothes to look alright!
Username Enumeration
Flip cardUsername enumeration is an attack where an attacker attempts to discover valid usernames on a system by observing differences in application responses (e.g., error messages, HTTP status codes, response times) when valid versus invalid usernames are submitted.
- Often a precursor to brute-force or credential stuffing attacks.
- Relies on subtle differences in error messages or response codes.
- Can be mitigated by generic error messages, rate limiting, and CAPTCHAs.
- Detected by monitoring repetitive login attempts with varying usernames.
Memory trick: Web log patterns are like reading a story of who's knocking on your web door, and why.
GDPR Principle: Integrity and Confidentiality
Flip cardOne of the seven core principles of GDPR, requiring personal data to be processed in a manner that ensures appropriate security against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.
- Also known as 'Security' principle.
- Requires 'appropriate technical or organisational measures'.
- Covers protection against unauthorized access, disclosure, alteration, or destruction.
- Directly impacted by data residency and transfer mechanisms.
Memory trick: GDPR's principles are like rules for handling data: keep it legal, limited, accurate, secure, and accountable.
Post-Engagement Cleanup
Flip cardThe final phase of a penetration test where all tools, backdoors, and modifications made by the tester are removed from the target systems.
- Ensures system integrity and security post-test.
- Prevents unauthorized access through tester-created artifacts.
- A crucial ethical responsibility of the penetration tester.
Memory trick: After the 'attack', you must 'clean up' and report.
Security Misconfiguration
Flip cardA common security vulnerability arising from improper setup or hardening of systems, applications, or networks, leading to exposed data or unauthorized access.
- Can occur at any level: OS, network devices, applications.
- Includes default configurations, open ports, unnecessary services.
- Often results from lack of security hardening or oversight.
- A top vulnerability in lists like OWASP Top 10.
Memory trick: Vulnerabilities are weak points, often due to misconfiguration or design flaws.
SSH (Secure Shell) Port 22
Flip cardSSH is a cryptographic network protocol for operating network services securely over an unsecured network. Its default port is TCP 22. Common uses include remote command-line login, remote command execution, and secure file transfers (SFTP).
- Provides strong encryption and authentication.
- Replaced insecure protocols like Telnet and rlogin.
- Often targeted by attackers for unauthorized remote access.
Memory trick: SSH is like a 'secure shore' for your remote connections, always on port 22.
Network Intrusion Prevention System (NIPS)
Flip cardA network security device that actively monitors network traffic for malicious activity or policy violations and automatically takes action to block, drop, or prevent such traffic in real-time. It sits inline with network traffic.
- Actively blocks/drops malicious traffic.
- Sits inline with network traffic.
- Prevents attacks in real-time.
- Can use signature, anomaly, or policy-based detection.
Memory trick: NIPS is the bouncer that actually stops the trouble.
SNMP Reconnaissance
Flip cardThe process of using Simple Network Management Protocol (SNMP) queries (often GetRequest messages) to discover devices, enumerate their configurations, and gather network information, often as a precursor to further attacks.
- Targets UDP port 161.
- Aims to extract sensitive information (e.g., system details, running services, network topology).
- Often involves trying default or common community strings.
Memory trick: Like a detective gathering clues before the main event.
Port Misuse
Flip cardPort misuse occurs when an attacker uses a standard, often allowed, network port (e.g., 80, 443, 53) for non-standard or malicious communication to evade detection.
- Evades firewall rules that allow standard ports.
- Often used by malware for command and control (C2).
- Detection requires deep packet inspection or behavioral analysis.
Memory trick: Anomalies are like traffic light violations: something's not right on the usual route.
DNS Exfiltration
Flip cardA type of data exfiltration that encodes sensitive data within DNS queries or responses, sending it to an attacker-controlled DNS server to bypass firewalls and intrusion detection systems.
- Leverages the DNS protocol (UDP port 53).
- Data is often Base64 encoded and embedded in subdomain names.
- Characterized by unusually long, malformed, or numerous DNS queries.
- Difficult to detect without deep packet inspection or DNS anomaly detection.
Memory trick: Data trying to sneak out, hidden in plain sight, using common services.
Data Exfiltration Indicators
Flip cardData exfiltration indicators are network or host-based signs that sensitive information is being illicitly transferred out of an organization's network.
- Unusually large outbound data transfers.
- Traffic to suspicious external IP addresses.
- Use of non-standard ports or protocols for data movement.
- Small, consistent packet sizes in outbound flows.
Memory trick: Intrusion indicators are like warning lights on your network dashboard.
Risk Mitigation (Compensating Control)
Flip cardThe process of reducing the likelihood or impact of a risk through the implementation of security controls, especially when direct remediation is not possible.
- Does not eliminate the vulnerability, but reduces its exploitability or impact.
- Often involves layered security (defense-in-depth).
- Requires careful selection and ongoing monitoring.
Memory trick: When you can't patch, 'shield' the weakness with other defenses.
Secure by Design
Flip cardA security principle that advocates for building security into systems and applications from the initial design phase, rather than adding it as an afterthought.
- Proactive approach to security.
- Integrates security throughout the SDLC.
- Reduces vulnerabilities and costs in the long run.
Memory trick: Design security in, don't just bolt it on later.
Application Sandboxing
Flip cardA security mechanism for separating running programs, usually to mitigate system failures or software vulnerabilities from spreading. It creates a tightly controlled environment (a 'sandbox') where an application can run, with limited access to system resources and other applications.
- Isolates applications from the operating system and other apps.
- Limits resource access (file system, network, memory).
- Used to contain untrusted code or isolate potentially malicious software.
Memory trick: Think of a child playing in a 'sandbox' – contained and unable to make a mess outside.
Policy Violation Detection
Flip cardPolicy violation detection is a security monitoring concept where systems are configured to identify and alert on activities that contravene established organizational security policies, rules, or baselines.
- Relies on predefined rules, whitelists, or blacklists.
- Can apply to data access, network connections, software usage, etc.
- Often implemented via SIEM rules, DLP (Data Loss Prevention) systems, or firewalls.
- Aims to enforce compliance and prevent unauthorized actions.
Memory trick: SIEM principles are like the 'rules of engagement' for your security data.
Isolation
Flip cardA security principle that involves separating resources, processes, or data to prevent a compromise in one area from affecting others. It helps to contain threats and limit the blast radius of an attack.
- Achieved through techniques like containerization, virtualization, and network segmentation.
- Minimizes the impact of a security incident.
- Enhances system resilience and reduces attack surface.
- A core component of secure system design.
Memory trick: Secure Design Isolates Privileged Layers
NTP Amplification Attack
Flip cardA type of Distributed Denial of Service (DDoS) attack that uses public Network Time Protocol (NTP) servers to overwhelm a target with UDP traffic.
- Leverages the NTP 'monlist' command or similar features that return large responses.
- Attackers spoof the target's IP address in requests to NTP servers.
- Results in a high volume of UDP traffic to the target on port 123.
Memory trick: Amplification: Small Request, Huge Response.
Data at Rest
Flip cardData that is stored physically in any digital form, such as on hard drives, USB drives, backup tapes, or cloud storage. Securing data at rest typically involves encryption.
- Refers to inactive data stored on any kind of storage device.
- Commonly secured using full disk encryption, file-level encryption, or database encryption.
- Critical for compliance with data protection regulations.
- Distinguished from data in transit and data in use.
Memory trick: Resting, Moving, Using Data
TLS (Transport Layer Security)
Flip cardA cryptographic protocol designed to provide communication security over a computer network. It is the successor to SSL and is widely used for securing web browsing (HTTPS), email, and other data transfers.
- Provides confidentiality, integrity, and authenticity.
- Uses both symmetric and asymmetric cryptography.
- Operates at the transport layer of the OSI model.
Memory trick: TLS makes web traffic safe, like a secure tunnel for your data.
Penetration Testing Exploitation Phase
Flip cardThe stage in penetration testing where identified vulnerabilities are actively exploited to gain unauthorized access, elevate privileges, or exfiltrate data, demonstrating the real-world impact of the flaws.
- Always conducted within defined scope and rules of engagement.
- Aims to prove exploitability and impact.
- Requires careful execution to avoid unintended damage.
Memory trick: Exploit with care, then show the scare.
Web Application Logs
Flip cardRecords generated by web servers and applications detailing HTTP requests, user activity, errors, and security-relevant events.
- Includes web server access logs, error logs, and application-specific audit logs.
- Crucial for detecting SQL injection, XSS, broken authentication, and other web attacks.
- Provides context for user behavior and application performance.
Memory trick: For a SIEM to truly see, logs from key places it must be!
GDPR Integrity & Confidentiality
Flip cardOne of the seven key principles of GDPR, requiring that personal data be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures.
- Often referred to as the 'security' principle.
- Mandates technical (e.g., encryption) and organizational (e.g., policies) measures.
- Aims to protect data from both intentional and accidental harm.
Memory trick: GDPR: Remember 'My Little Pony Loves ICE-T' for the seven principles, where ICE-T covers Integrity, Confidentiality, and Accountability.
DDoS Attack Participation (Bot)
Flip cardWhen a compromised host (a 'bot') is controlled by an attacker to send high volumes of traffic to a target, contributing to a Distributed Denial of Service (DDoS) attack, often leading to resource starvation on the bot itself.
- High volume of outbound traffic from a single internal host.
- Traffic destined for multiple external targets.
- Often uses UDP or SYN floods.
- Impacts the compromised host's normal operations.
Memory trick: A stressed host, like a runner, has less energy for other tasks.
DNS Tunneling
Flip cardA method of data exfiltration or command-and-control communication that encodes data within DNS queries and responses to bypass security controls.
- Uses UDP port 53, often to non-authoritative DNS servers.
- Characterized by small queries and potentially large, fragmented responses.
- Can be used for C2, data exfiltration, or bypassing firewalls.
Memory trick: Secret data slipping out through unexpected channels.
Implicit Deny
Flip cardA security principle, most commonly applied in firewalls and access control lists (ACLs), where any access or traffic that is not explicitly permitted by a rule is automatically denied. This ensures that only authorized actions or communications are allowed.
- Last rule in most firewall rule sets (invisible).
- Ensures security by default, preventing unapproved access.
- Opposite of 'implicit allow' (which is highly insecure).
Memory trick: Implicit Deny is like having a 'No Entry' sign everywhere unless there's a specific 'Entry Permitted' sign.
Non-Intrusive Scan
Flip cardA type of vulnerability scan that identifies potential weaknesses without actively exploiting them or causing disruption to systems.
- Focuses on information gathering, not exploitation.
- Safer for production environments.
- May result in more false positives than intrusive scans.
Memory trick: Non-intrusive scans are like a careful librarian, checking books without tearing pages.
Smurf Attack
Flip cardA DDoS attack where an attacker spoofs the victim's IP address and sends ICMP echo requests to a network's broadcast address, causing all hosts on that network to reply to the victim, overwhelming them.
- Uses ICMP echo requests (ping).
- Involves IP address spoofing.
- Leverages an intermediary network's broadcast address.
- Results in a Denial of Service (DoS) for the target.
Memory trick: Denial of Service impacts availability, like a Smurf overwhelming with pings.
Agent-based vs. Agentless Scanning
Flip cardTwo primary methods of vulnerability scanning: agent-based installs a lightweight program on each target, while agentless scans targets remotely without local software installation.
- Agent-based: continuous, deep insights, good for dynamic assets.
- Agentless: less overhead, broader reach, good for stable assets.
- Choice depends on environment, asset type, and monitoring needs.
Memory trick: Agent inside, or scan from outside.
Threat Modeling
Flip cardA structured process for identifying, quantifying, and mitigating security threats relevant to a system during its design and development phases. It helps in proactively building security into the architecture.
- Performed early in the Software Development Life Cycle (SDLC).
- Helps identify potential attack vectors and vulnerabilities.
- Involves analyzing the system's architecture, data flows, and trust boundaries.
- A key component of the 'secure by design' principle.
Memory trick: Design Securely, Model Threats Early
SSH Brute-force Attack
Flip cardAn attack targeting the Secure Shell (SSH) protocol (typically on port 22) where an attacker attempts to gain unauthorized access to a server by systematically trying many possible usernames and passwords until the correct combination is found. This often involves automated tools.
- Targets SSH (port 22).
- Involves multiple failed login attempts.
- Aims to guess valid credentials.
- Often automated using password lists/dictionaries.
Memory trick: Port 22 + Failed logins = SSH Brute-force always tries the lock repeatedly.
Cyber Kill Chain - Actions on Objectives
Flip cardThe 'Actions on Objectives' phase of the Cyber Kill Chain encompasses the steps an attacker takes to achieve their ultimate goals after gaining access to a target system, such as data exfiltration, destruction, or gaining further control.
- Occurs after successful exploitation and installation.
- Involves activities like data theft, privilege escalation, lateral movement, or system sabotage.
- Directly aligns with the attacker's original intent.
- Detection focuses on monitoring for unusual data access, command execution, or configuration changes.
Memory trick: The Kill Chain is like a step-by-step guide for an attacker's journey.
Patch Management
Flip cardThe process of acquiring, testing, and applying code changes (patches) to software and systems to fix bugs, enhance features, and, most importantly, address security vulnerabilities.
- Crucial for maintaining system security.
- Involves regular monitoring for new patches.
- Requires testing before widespread deployment.
Memory trick: Patching up holes keeps systems whole.
Masquerading Process
Flip cardA masquerading process is a malicious program that disguises itself with the name of a legitimate system process or application to evade detection by security tools and users.
- Often runs from unusual directories (e.g., temp folders, user profiles).
- May have unusual parent processes.
- Exhibits suspicious network connections or resource usage.
- Requires verifying process path, digital signature, and parentage.
Memory trick: Process anomalies are like finding a 'ghost' in your computer's machine room.
Anomaly-based Detection
Flip cardA security detection method that establishes a baseline of normal system or user behavior and then identifies deviations from this baseline as potential security incidents. It is effective at detecting unknown or zero-day threats that do not have existing signatures.
- Builds a baseline of 'normal'.
- Flags deviations from the baseline.
- Effective against unknown/zero-day threats.
- Can generate false positives.
Memory trick: Anomaly detection is like noticing your cat suddenly wearing a tiny hat.