Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium

A security analyst is performing host-based forensics on a Linux server after a suspected compromise. The analyst discovers an unfamiliar executable file in a /tmp directory that has been running for an extended period. To determine if this executable is indeed malicious and to understand its behavior, which of the following host-based analysis techniques would provide the most immediate and comprehensive insight without altering the live system significantly?

  1. AExecuting the file in a sandbox environment to observe its network and file system interactions.
  2. BPerforming a full disk image of the server for offline analysis.
  3. CAnalyzing the process's open files and network connections using 'lsof' and 'netstat'.
  4. DReviewing the Apache web server access logs for unusual HTTP requests.
Show answer & explanation

Correct answer: C. Analyzing the process's open files and network connections using 'lsof' and 'netstat'.

Analyzing open files and network connections using tools like 'lsof' and 'netstat' provides immediate, real-time insight into the suspicious process's current activities on the live system without significantly altering its state. This helps understand its behavior before considering more intrusive or time-consuming methods.

Why the other options are wrong

  • A. Executing in a sandbox is dynamic analysis, but the question asks about understanding behavior on the *live system* without altering it significantly. A sandbox is an external environment.
  • B. A full disk image is crucial for deep forensic analysis but is time-consuming and doesn't provide immediate, real-time insight into the running process's current behavior.
  • D. Apache logs would show web traffic, but not necessarily the actions of an arbitrary executable in /tmp unless it's specifically a web server component or interacting with it in a logged manner.

Live System Analysis (Linux)

Examining a running Linux system to gather real-time data about processes, network connections, and open files without stopping or altering critical system functions.

  • Focuses on volatile data.
  • Uses commands like 'ps', 'netstat', 'lsof', 'ss'.
  • Aims to understand current system state and ongoing activities.

Memory trick: Linux live investigations look for active system states.

More Host-Based Analysis questions