Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium
A security analyst is investigating a Windows server that was recently involved in a data exfiltration incident. The attacker is believed to have used a living-off-the-land binary (LOLBIN) to compress and stage data before exfiltration. The analyst needs to identify if and how 'makecab.exe' was used. Which of the following host-based artifacts would be most critical for determining the command-line arguments passed to 'makecab.exe'?
- AWindows Security Event Log, Event ID 5145 (Detailed File Share Access)
- BMicrosoft-Windows-PowerShell/Operational log for cmdlets.
- CSysmon Event ID 1 (Process Create) in the Microsoft-Windows-Sysmon/Operational log.
- DPrefetch files (.pf) associated with 'makecab.exe'.
Show answer & explanationAnswer & explanation
Correct answer: C. Sysmon Event ID 1 (Process Create) in the Microsoft-Windows-Sysmon/Operational log.
Sysmon Event ID 1 (Process Create) is specifically designed to capture detailed information about every process launch, including the full command-line arguments used. This is crucial for understanding how 'makecab.exe' was invoked and what files it might have processed or compressed, which aligns directly with investigating LOLBIN usage for data staging.
Why the other options are wrong
- A. Event ID 5145 logs detailed access to shared files/folders, not the command-line arguments of processes that might interact with those files.
- B. The PowerShell operational log records PowerShell cmdlets, but 'makecab.exe' is a separate executable, and its direct command-line arguments wouldn't typically be in this log unless PowerShell explicitly invoked it and logged the full command.
- D. Prefetch files record executable launch information (e.g., path, launch count) for performance optimization, but they do not typically store the full command-line arguments used for each invocation.
LOLBIN Command Line Analysis
Analyzing the command-line arguments of legitimate system binaries (LOLBINs) to detect malicious usage, often facilitated by detailed process creation logs like Sysmon Event ID 1.
- LOLBINs are legitimate tools used maliciously.
- Command-line arguments reveal their specific malicious function.
- Sysmon Event ID 1 is ideal for capturing this detail.
Memory trick: LOLBINs hide in plain sight, command lines tell the tale.