CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium

A security analyst is investigating a potential compromise on a Linux server. They suspect a malicious process is attempting to hide its activity. The analyst runs the 'ps aux' command and sees the following output snippet: ``` USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND root 1 0.0 0.0 170900 9208 ? Ss Oct01 0:02 /sbin/init user1 12345 0.1 0.2 123456 12345 ? S Oct02 0:05 /usr/bin/python3 /tmp/.hidden/malware.py root 23456 0.0 0.1 10000 1000 ? R 10:30 0:00 [kworker/u8:0-events] ``` Based on this output, which of the following is the MOST suspicious indicator of compromise?

  1. AProcess `1` running as `root` with `/sbin/init`.
  2. BProcess `23456` named `[kworker/u8:0-events]` running as `root`.
  3. CThe `STAT` column showing `Ss` for `init` and `S` for `user1`'s process.
  4. DProcess `12345` running as `user1` executing a Python script from `/tmp`.
Show answer & explanation

Correct answer: D. Process `12345` running as `user1` executing a Python script from `/tmp`.

A Python script running from the `/tmp` directory (a common location for temporary files and malware drops) and specifically named `malware.py` under an unprivileged user's context is a strong indicator of compromise. Valid system processes typically don't run from `/tmp` with such descriptive names.

Why the other options are wrong

  • A. Process 1 (`init`) running as `root` is normal for a Linux system, indicating the parent of all processes.
  • B. Processes like `kworker` in square brackets are kernel threads and are normal system operations, even when running as `root`.
  • C. The `STAT` column values `Ss` (session leader) and `S` (interruptible sleep) are common process states and not inherently suspicious without other context.

Linux Process Analysis

Examining running processes on a Linux system for anomalous behavior, resource usage, or suspicious origins.

  • Look for unusual parent-child relationships.
  • Check process paths, especially /tmp or user home directories.
  • Monitor resource consumption for spikes.

Memory trick: Check Processes (paths!), Logs (errors!), and Network (odd ports!).

More Incident Response and Management questions