CompTIA CySA+ (CS0-003)Security OperationsEasy
A security analyst is building a threat hunting hypothesis focused on detecting advanced persistent threats (APTs). The analyst wants to gain deeper visibility into process creation, network connections, and file modifications on Windows endpoints, beyond what standard Windows Event Logs provide. Which tool would be most effective for this purpose?
- ASnort
- BNmap
- CWireshark
- DSysmon
Show answer & explanationAnswer & explanation
Correct answer: D. Sysmon
Sysmon (System Monitor) is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event log. It provides detailed information about process creations, network connections, and changes to file creation time, which are crucial for advanced threat hunting.
Why the other options are wrong
- A. Snort is a network intrusion detection system (NIDS), focusing on network traffic signatures, not endpoint forensics.
- B. Nmap is a network scanner, not an endpoint logging tool.
- C. Wireshark is a packet analyzer, primarily for network traffic, not detailed endpoint process activity.
Sysmon (System Monitor)
A Windows system service and device driver that monitors and logs system activity to the Windows event log, providing detailed information about process creations, network connections, and file modifications.
- Part of Sysinternals suite from Microsoft.
- Provides deeper endpoint visibility than standard Windows Event Logs.
- Configurable via XML files to specify events to monitor.
Memory trick: Sysmon monitors system actions on endpoints.