CompTIA SecurityX (CAS-005)Security OperationsHard
An incident response team is investigating a critical server compromise. They have obtained a memory dump from the affected system. To determine if a rootkit is actively hiding processes or network connections, which forensic technique would be most effective?
- AAnalyzing filesystem timestamps for recently modified files.
- BComparing kernel module lists from the memory dump with a known good baseline.
- CReviewing web server access logs for unusual HTTP requests.
- DExtracting user account hashes from the SAM database.
Show answer & explanationAnswer & explanation
Correct answer: B. Comparing kernel module lists from the memory dump with a known good baseline.
Rootkits often operate at the kernel level to hide their presence. By comparing the loaded kernel modules identified in a memory dump against a known good baseline, an investigator can detect malicious or unauthorized modules that indicate rootkit activity, which might be masking processes or network connections.
Why the other options are wrong
- A. Analyzing filesystem timestamps helps detect file manipulation but is less effective against kernel-level rootkits that hide files/processes.
- C. Reviewing web server access logs would help identify web-based attacks but not kernel-level rootkits hiding processes or network activity.
- D. Extracting user account hashes from the SAM database is relevant for credential compromise but does not directly reveal the presence of a rootkit hiding processes or network connections.
Kernel Rootkit Detection
The process of identifying malicious software (rootkits) that operates at the kernel level of an operating system to hide its presence and activities from detection tools.
- Requires kernel-level visibility (e.g., memory forensics).
- Often involves comparing active kernel structures to a known good state.
- Can hide processes, files, network connections.
- Challenges traditional OS-level detection methods.
Memory trick: To find the ghost in the machine's brain, you need to look at its core components.