Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisEasy
A security analyst is investigating a Windows workstation that is exhibiting unusual network activity, including frequent connections to an unknown external IP address. The analyst suspects a persistent malware infection. Which of the following host-based artifacts would be most indicative of a malware establishing persistence through a service?
- AEntries in the 'Recycle Bin' directory indicating recently deleted files.
- BHigh CPU utilization reported by the Task Manager for a legitimate system process.
- CA newly created service entry in the Windows Registry under HKLM\SYSTEM\CurrentControlSet\Services.
- DMultiple failed login attempts recorded in the Security Event Log.
Show answer & explanationAnswer & explanation
Correct answer: C. A newly created service entry in the Windows Registry under HKLM\SYSTEM\CurrentControlSet\Services.
Malware often establishes persistence by creating new services that automatically start with the system. These service entries are recorded in the Windows Registry, specifically under the HKLM\SYSTEM\CurrentControlSet\Services path, making them a primary indicator of such activity.
Why the other options are wrong
- A. Recycle Bin entries are related to user file deletion and not directly indicative of malware persistence mechanisms.
- B. High CPU utilization for a legitimate process could indicate various issues, but not specifically service-based malware persistence.
- D. Failed login attempts point to potential brute-force attacks or credential stuffing, not service-based malware persistence.
Windows Service Persistence
Malware can achieve persistence on a Windows system by creating or modifying service entries in the Registry, ensuring its execution upon system startup.
- Services automatically start with the system.
- Registry key HKLM\SYSTEM\CurrentControlSet\Services stores service configurations.
- Unusual service entries can indicate malware.
Memory trick: Many malware make systems start services.