Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisHard

A security analyst is investigating a Windows workstation where sensitive data is suspected to have been exfiltrated. The attacker likely used living-off-the-land binaries (LOLBINs) to avoid detection. The analyst needs to identify unusual command-line executions that might indicate the use of such tools for data staging or exfiltration. Which of the following host-based logging configurations would be most critical to enable for this investigation?

  1. AEnable auditing of successful and failed logon events.
  2. BIncrease the size of the Security event log to 100 MB.
  3. CConfigure Windows Firewall logging to capture dropped packets.
  4. DEnable 'Audit Process Creation' (Event ID 4688) with 'Include Command Line in Process Creation Events'.
Show answer & explanation

Correct answer: D. Enable 'Audit Process Creation' (Event ID 4688) with 'Include Command Line in Process Creation Events'.

LOLBINs are legitimate system tools misused by attackers. To detect their malicious use, it's crucial to log the full command line arguments, as these often reveal the attacker's intent. 'Audit Process Creation' (Event ID 4688) with command-line auditing enabled provides this granular detail, allowing the analyst to identify suspicious parameters passed to legitimate executables.

Why the other options are wrong

  • A. Logon events are important for authentication analysis but don't provide details about command-line execution of LOLBINs.
  • B. Increasing log size is good practice but without the correct logging configuration, it won't capture the necessary command-line details for LOLBIN detection.
  • C. Windows Firewall logging captures network connection attempts but not the specific command-line activities on the host.

LOLBIN Command Line Auditing

The practice of configuring endpoint logging to capture the full command-line arguments of executed processes to detect the malicious use of legitimate system binaries (LOLBINs).

  • Crucial for detecting LOLBIN misuse
  • Requires 'Audit Process Creation' (Event ID 4688)
  • Captures full command-line arguments

Memory trick: To catch the LOLBIN, you must read its full command line story.

More Host-Based Analysis questions