Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisHard

A security analyst is investigating a compromised Linux server and suspects the attacker has manipulated dynamic linker preloading (LD_PRELOAD) to redirect system calls for malicious purposes. Which of the following host-based forensic steps would be most effective in identifying if LD_PRELOAD is being used by a running process?

  1. AExamining the 'PATH' environment variable of the suspicious process for unusual directories.
  2. BAnalyzing the output of 'lsof -p <PID>' for the suspicious process and looking for loaded shared libraries.
  3. CChecking the '/etc/ld.so.preload' file for suspicious entries.
  4. DReviewing '/var/log/audit/audit.log' for 'execve' system calls.
Show answer & explanation

Correct answer: B. Analyzing the output of 'lsof -p <PID>' for the suspicious process and looking for loaded shared libraries.

While '/etc/ld.so.preload' is a global configuration, attackers often use LD_PRELOAD environment variables specific to a process to avoid global detection. The 'lsof -p <PID>' command can show all open files and loaded shared libraries for a specific running process, including those loaded via LD_PRELOAD, thereby revealing the malicious library's presence for that process.

Why the other options are wrong

  • A. The 'PATH' environment variable affects where executables are searched, not which dynamic libraries are preloaded by a running process.
  • C. Checking '/etc/ld.so.preload' is a good step, but LD_PRELOAD can also be set as an environment variable for individual processes, which this global file wouldn't reveal.
  • D. 'execve' system calls in audit logs indicate process execution, but not directly whether LD_PRELOAD was used or which libraries were preloaded.

LD_PRELOAD Abuse Detection

Detecting malicious use of LD_PRELOAD, which forces a process to load a specified shared library before any others, often used by attackers for rootkit-like functionality or privilege escalation.

  • LD_PRELOAD can be global or per-process.
  • Allows interception of system calls.
  • Revealed by examining a process's loaded libraries.

Memory trick: Libraries can be preloaded; 'lsof' shows the load.

More Host-Based Analysis questions