Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringHard

A security analyst is investigating a series of alerts from an Endpoint Detection and Response (EDR) solution indicating a suspicious process attempting to inject code into another legitimate process on a Windows host. The legitimate process is 'explorer.exe'. What is this type of activity commonly referred to in host-based intrusion analysis?

  1. ARootkit Installation
  2. BPrivilege Escalation
  3. CDLL Sideloading
  4. DProcess Hollowing
Show answer & explanation

Correct answer: D. Process Hollowing

Process hollowing is a sophisticated evasion technique where a legitimate process is started in a suspended state, its original code is unmapped, and malicious code is written into its memory space before the process is resumed. This is a common way for malware to hide by masquerading as a legitimate process.

Why the other options are wrong

  • A. Rootkit installation aims to achieve persistent, stealthy control over a system, but 'injecting code into another legitimate process' describes a specific technique rather than the broader goal of a rootkit.
  • B. Privilege escalation aims to gain higher access rights, not specifically inject code into a process in this manner.
  • C. DLL sideloading involves placing a malicious DLL in a location where a legitimate application will load it instead of the intended DLL.

Process Hollowing

A stealthy malware injection technique where a legitimate process is created in a suspended state, its memory is unmapped, malicious code is written into its place, and the process is then resumed.

  • Allows malware to run under the identity of a trusted process.
  • Evades traditional signature-based detection.
  • Often involves modifying the legitimate process's entry point.

Memory trick: Malware hides on the host, playing tricks to avoid being lost!

More Security Monitoring questions