Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringHard
A security analyst is investigating a series of alerts from an Endpoint Detection and Response (EDR) solution indicating a suspicious process attempting to inject code into another legitimate process on a Windows host. The legitimate process is 'explorer.exe'. What is this type of activity commonly referred to in host-based intrusion analysis?
- ARootkit Installation
- BPrivilege Escalation
- CDLL Sideloading
- DProcess Hollowing
Show answer & explanationAnswer & explanation
Correct answer: D. Process Hollowing
Process hollowing is a sophisticated evasion technique where a legitimate process is started in a suspended state, its original code is unmapped, and malicious code is written into its memory space before the process is resumed. This is a common way for malware to hide by masquerading as a legitimate process.
Why the other options are wrong
- A. Rootkit installation aims to achieve persistent, stealthy control over a system, but 'injecting code into another legitimate process' describes a specific technique rather than the broader goal of a rootkit.
- B. Privilege escalation aims to gain higher access rights, not specifically inject code into a process in this manner.
- C. DLL sideloading involves placing a malicious DLL in a location where a legitimate application will load it instead of the intended DLL.
Process Hollowing
A stealthy malware injection technique where a legitimate process is created in a suspended state, its memory is unmapped, malicious code is written into its place, and the process is then resumed.
- Allows malware to run under the identity of a trusted process.
- Evades traditional signature-based detection.
- Often involves modifying the legitimate process's entry point.
Memory trick: Malware hides on the host, playing tricks to avoid being lost!