CompTIA CySA+ (CS0-003)Security OperationsMedium
A security analyst is investigating a suspected malware infection on a Windows workstation. The EDR solution reports a process named `svchost.exe` running from `C:\Users\Public\Documents\malware.exe`, which is an unusual location for this legitimate system process. Additionally, the process is making outbound connections to a known malicious IP address. What defense evasion technique is the attacker most likely employing?
- AHooking
- BMasquerading
- CDLL Side-Loading
- DProcess Hollowing
Show answer & explanationAnswer & explanation
Correct answer: B. Masquerading
Masquerading (T1036) involves renaming or relocating legitimate system binaries or using legitimate process names for malicious executables to blend in with normal system activity and evade detection. Running `malware.exe` but naming its process `svchost.exe` and placing it in an unusual directory (`C:\Users\Public\Documents\`) perfectly fits this description.
Why the other options are wrong
- A. Hooking involves intercepting function calls within a system or application, not disguising a malicious executable.
- C. DLL side-loading involves placing a malicious DLL in a location where a legitimate application will load it, not renaming an executable.
- D. Process hollowing involves injecting malicious code into a legitimate suspended process, not renaming an executable.
Masquerading (Defense Evasion)
A defense evasion technique where an adversary renames or relocates legitimate system utilities or uses legitimate process names for malicious executables to avoid detection.
- Relies on blending in with normal system activity.
- Often involves common system processes (e.g., svchost.exe, explorer.exe).
- Indicators include unusual paths or parent processes for legitimate-looking executables.
Memory trick: Attackers hide by looking normal or changing behavior.