Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium
A security analyst is performing host-based forensics on a Linux server after a suspected compromise. The analyst discovers an unfamiliar executable file in a /tmp directory that has been running for an extended period. To determine if this executable is indeed malicious and to understand its behavior, which of the following host-based analysis techniques would provide the most immediate and comprehensive insight without altering the live system significantly?
- AExecuting the file in a sandbox environment to observe its network and file system interactions.
- BPerforming a full disk image of the server for offline analysis.
- CAnalyzing the process's open files and network connections using 'lsof' and 'netstat'.
- DReviewing the Apache web server access logs for unusual HTTP requests.
Show answer & explanationAnswer & explanation
Correct answer: C. Analyzing the process's open files and network connections using 'lsof' and 'netstat'.
Analyzing open files and network connections using tools like 'lsof' and 'netstat' provides immediate, real-time insight into the suspicious process's current activities on the live system without significantly altering its state. This helps understand its behavior before considering more intrusive or time-consuming methods.
Why the other options are wrong
- A. Executing in a sandbox is dynamic analysis, but the question asks about understanding behavior on the *live system* without altering it significantly. A sandbox is an external environment.
- B. A full disk image is crucial for deep forensic analysis but is time-consuming and doesn't provide immediate, real-time insight into the running process's current behavior.
- D. Apache logs would show web traffic, but not necessarily the actions of an arbitrary executable in /tmp unless it's specifically a web server component or interacting with it in a logged manner.
Live System Analysis (Linux)
Examining a running Linux system to gather real-time data about processes, network connections, and open files without stopping or altering critical system functions.
- Focuses on volatile data.
- Uses commands like 'ps', 'netstat', 'lsof', 'ss'.
- Aims to understand current system state and ongoing activities.
Memory trick: Linux live investigations look for active system states.