CompTIA CySA+ (CS0-003)Security OperationsMedium

A security analyst is investigating a suspected malware infection on a Windows workstation. The EDR solution reports a process named `svchost.exe` running from `C:\Users\Public\Documents\malware.exe`, which is an unusual location for this legitimate system process. Additionally, the process is making outbound connections to a known malicious IP address. What defense evasion technique is the attacker most likely employing?

  1. AHooking
  2. BMasquerading
  3. CDLL Side-Loading
  4. DProcess Hollowing
Show answer & explanation

Correct answer: B. Masquerading

Masquerading (T1036) involves renaming or relocating legitimate system binaries or using legitimate process names for malicious executables to blend in with normal system activity and evade detection. Running `malware.exe` but naming its process `svchost.exe` and placing it in an unusual directory (`C:\Users\Public\Documents\`) perfectly fits this description.

Why the other options are wrong

  • A. Hooking involves intercepting function calls within a system or application, not disguising a malicious executable.
  • C. DLL side-loading involves placing a malicious DLL in a location where a legitimate application will load it, not renaming an executable.
  • D. Process hollowing involves injecting malicious code into a legitimate suspended process, not renaming an executable.

Masquerading (Defense Evasion)

A defense evasion technique where an adversary renames or relocates legitimate system utilities or uses legitimate process names for malicious executables to avoid detection.

  • Relies on blending in with normal system activity.
  • Often involves common system processes (e.g., svchost.exe, explorer.exe).
  • Indicators include unusual paths or parent processes for legitimate-looking executables.

Memory trick: Attackers hide by looking normal or changing behavior.

More Security Operations questions