CompTIA SecurityX (CAS-005)Security OperationsHard

A security analyst is investigating a compromised endpoint. They suspect that a malicious process is attempting to hide its activity by unlinking itself from the process list and manipulating system calls. Which advanced forensic technique would be most effective in detecting such a rootkit-like behavior?

  1. AReviewing system logs for unusual login attempts.
  2. BPerforming kernel-level memory forensics to compare process lists.
  3. CRunning an antivirus scan with up-to-date signatures.
  4. DAnalyzing standard `ps` and `top` command outputs.
Show answer & explanation

Correct answer: B. Performing kernel-level memory forensics to compare process lists.

Rootkits often hide processes by manipulating kernel data structures, making them invisible to standard user-mode tools like `ps` or `top`. Kernel-level memory forensics (C), which involves analyzing a raw memory dump, can detect these hidden processes by comparing the kernel's internal process list with what user-mode tools report, thus revealing the rootkit's presence. The other options would likely be ineffective against such sophisticated hiding techniques.

Why the other options are wrong

  • A. Unusual login attempts are a different indicator and do not directly detect hidden processes.
  • C. Antivirus scans primarily rely on signatures or heuristics and may not detect novel or highly obfuscated rootkits that manipulate kernel structures.
  • D. Standard `ps` and `top` commands operate in user mode and can be fooled by kernel-level rootkits.

Kernel-Level Memory Forensics

The analysis of a raw memory dump (RAM image) from a compromised system, specifically focusing on kernel data structures and memory regions. This technique is crucial for detecting sophisticated malware like rootkits that hide processes, files, or network connections by subverting the operating system kernel.

  • Analyzes raw RAM dumps.
  • Examines kernel data structures.
  • Detects hidden processes and rootkits.
  • Requires specialized tools (e.g., Volatility Framework).

Memory trick: To Catch a Hidden Rootkit, You Need Kernel Memory Forensics.

More Security Operations questions