CompTIA SecurityX (CAS-005)Security OperationsHard

A forensic investigator is analyzing a compromised Linux server. They have created a memory dump and identified several suspicious processes. To determine if any of these processes are attempting to hide their activities by unlinking their executable files, which of the following techniques should the investigator use?

  1. AAnalyze network connections associated with the processes using `netstat` output from the memory dump.
  2. BExtract the process environment variables to identify suspicious configurations.
  3. CLook for specific entries in `/var/log/auth.log` that indicate privilege escalation.
  4. DExamine the process's `cwd` (current working directory) and `exe` (executable path) symbolic links in `/proc/<PID>/` within the memory dump.
Show answer & explanation

Correct answer: D. Examine the process's `cwd` (current working directory) and `exe` (executable path) symbolic links in `/proc/<PID>/` within the memory dump.

On Linux, when an executable is deleted (unlinked) while a process is still running, the `/proc/<PID>/exe` symbolic link will typically point to a 'deleted' file, and the original file path might not exist on disk. Examining these specific symbolic links and the `cwd` within a memory dump (using tools like Volatility) is the most direct way to detect unlinked executables.

Why the other options are wrong

  • A. Network connections are important but don't directly reveal if an executable file has been unlinked.
  • B. Environment variables might contain clues but are not a direct indicator of an unlinked executable.
  • C. Auth logs indicate authentication events and privilege escalation, not specifically if a running process's executable has been unlinked.

Linux Process Forensics (/proc)

The `/proc` filesystem in Linux is a virtual filesystem that provides an interface to kernel data structures, allowing forensic investigators to examine running processes, their memory maps, open files, and other runtime information.

  • Each process has a directory `/proc/<PID>/`.
  • Contains `exe` (executable path), `cwd` (current working directory), `maps` (memory maps).
  • Crucial for analyzing live system state and memory dumps.

Memory trick: Linux processes leave clues in /proc, even when deleted.

More Security Operations questions