Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisEasy
A security analyst is investigating a Windows workstation that is exhibiting unusual network activity and process behavior. The analyst suspects a sophisticated malware infection. Which of the following host-based tools is best suited for identifying hidden processes, kernel-mode rootkits, and injected code on a live Windows system?
- ASysinternals Process Explorer
- Bnetstat
- CEvent Viewer
- Dtasklist
Show answer & explanationAnswer & explanation
Correct answer: A. Sysinternals Process Explorer
Sysinternals Process Explorer is a powerful tool for Windows that provides detailed information about running processes, including parent-child relationships, loaded modules, and can identify hidden processes or those with injected code. It offers more depth than basic command-line tools for advanced malware analysis.
Why the other options are wrong
- B. netstat is used for displaying active network connections, not for identifying hidden processes or kernel-mode rootkits.
- C. Event Viewer collects system logs but does not directly identify hidden processes or kernel-mode rootkits in real-time.
- D. tasklist lists running processes but lacks the deep inspection capabilities needed to detect hidden or injected code.
Sysinternals Process Explorer
A free utility from Microsoft that provides advanced process management and analysis capabilities for Windows operating systems.
- Displays hierarchical process tree
- Shows loaded DLLs and handles
- Can identify hidden or injected code
Memory trick: Process Explorer is your magnifying glass for Windows processes.