CompTIA CySA+ (CS0-003)Security OperationsMedium

A security analyst is building a threat hunting hypothesis focused on detecting advanced persistent threats (APTs). The analyst suspects that an APT might be using legitimate system utilities for living-off-the-land techniques to evade detection. The analyst wants to specifically look for instances where `rundll32.exe` is used to load arbitrary DLLs from non-standard locations or with unusual command-line arguments. Which of the following log sources would be MOST effective for detecting this specific activity?

  1. ASysmon (Event ID 1 - Process Creation, Event ID 7 - Image Loaded)
  2. BFirewall Connection Logs
  3. CDNS Server Query Logs
  4. DWindows Security Event Log (Event ID 4624 - Logon)
Show answer & explanation

Correct answer: A. Sysmon (Event ID 1 - Process Creation, Event ID 7 - Image Loaded)

Sysmon is specifically designed to provide detailed system activity monitoring, including process creation (Event ID 1) with full command lines and module/image loading (Event ID 7). These events would capture the execution of `rundll32.exe`, its command-line arguments (showing the DLL path), and the loading of the suspicious DLL, making it ideal for detecting this specific living-off-the-land technique.

Why the other options are wrong

  • B. Firewall logs track network connections but would not show the internal process execution details of `rundll32.exe` or the DLL being loaded.
  • C. DNS logs track domain name resolutions and would not provide information about local process execution or DLL loading, only potential C2 communication if `rundll32.exe` were to initiate network activity.
  • D. Event ID 4624 logs successful account logons and would not provide details about process execution or DLL loading.

Sysmon

Sysmon (System Monitor) is a Windows system service and device driver that, once installed on a computer, remains resident across system reboots to monitor and log system activity to the Windows event log. It provides detailed information about process creations, network connections, and changes to file creation time.

  • Provides granular visibility into system activities.
  • Captures process creation with full command lines.
  • Logs network connections, driver loads, and image loads.

Memory trick: Endpoint logs tell the story of what happens inside a machine.

More Security Operations questions