Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium
A security analyst is performing a host-based investigation on a server that was recently compromised. During the analysis, the analyst discovers several scheduled tasks that were created by an unknown user, configured to run PowerShell scripts at regular intervals. Which common malware persistence mechanism does this scenario most clearly represent?
- AScheduled tasks/Jobs
- BDLL sideloading
- CBrowser helper objects (BHOs)
- DRootkit installation
Show answer & explanationAnswer & explanation
Correct answer: A. Scheduled tasks/Jobs
Creating scheduled tasks or cron jobs is a very common and effective malware persistence mechanism, allowing attackers to ensure their malicious code executes periodically or at specific times, even after a system reboot, without requiring direct user interaction.
Why the other options are wrong
- B. DLL sideloading exploits legitimate applications to load malicious DLLs, but it's not directly related to scheduled execution.
- C. Browser helper objects (BHOs) are plugins for Internet Explorer, used for browser-based persistence, not general system execution.
- D. Rootkit installation aims to hide malicious activity from the OS and users, which is a broader concept than just scheduled execution.
Scheduled Task Persistence
A malware persistence technique where malicious code is configured to execute automatically at specific intervals or times using legitimate operating system scheduling features.
- Utilizes Windows Task Scheduler or Linux Cron Jobs.
- Ensures malicious code runs even after reboots.
- Can be used for command and control, data exfiltration, or further infection.
Memory trick: To stay hidden, malware can 'schedule' its reappearance, 'hijack' a path, or 'hide' in plain sight.