Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium

A security operations center (SOC) analyst is investigating an alert from an Endpoint Detection and Response (EDR) system indicating a suspicious process injection on a Windows server. The alert points to a legitimate svchost.exe process exhibiting unusual child processes and network connections. To further investigate this, the analyst needs to capture detailed information about the affected process and its memory. Which of the following tools or techniques is most appropriate for acquiring a memory dump of a specific process on a live Windows system for offline analysis?

  1. AUsing task manager to end the svchost.exe process.
  2. BEmploying Process Explorer or procdump to capture a memory dump of the specific svchost.exe process.
  3. CRunning 'netstat -ano' to list network connections.
  4. DExecuting 'sfc /scannow' to repair system files.
Show answer & explanation

Correct answer: B. Employing Process Explorer or procdump to capture a memory dump of the specific svchost.exe process.

Process Explorer and procdump are powerful Sysinternals tools that allow an analyst to capture a memory dump of a specific running process. This dump can then be analyzed offline using memory forensics tools (like Volatility) to uncover injected code, hidden modules, and other malicious artifacts without disrupting the live system significantly.

Why the other options are wrong

  • A. Ending the process would destroy crucial forensic evidence and potentially crash the system, making analysis impossible.
  • C. netstat -ano lists network connections but does not capture memory or process details needed for injection analysis.
  • D. sfc /scannow checks and repairs system file integrity but is not used for capturing live process memory or investigating process injection.

Process Memory Dump

A snapshot of the memory space used by a specific running process at a given time, essential for detailed malware analysis and forensic investigations.

  • Captures injected code and hidden modules
  • Analyzed offline with specialized tools
  • Tools: Process Explorer, procdump

Memory trick: To see inside, dump the process mind.

More Host-Based Analysis questions