Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisHard

A security analyst is performing host-based forensics on a Linux workstation. The workstation is suspected of being compromised by a rootkit that hides malicious processes. Which command-line utility, by inspecting kernel-level structures, is specifically designed to detect hidden processes that standard tools like `ps aux` might not reveal?

  1. Achkrootkit
  2. Bnetstat
  3. Ctop
  4. Dlsof
Show answer & explanation

Correct answer: A. chkrootkit

`chkrootkit` is a common Unix-based tool specifically designed to scan for rootkits, including those that attempt to hide processes, files, or network activity by manipulating kernel-level data structures or system calls. It does this by comparing system calls against expected output and looking for anomalies.

Why the other options are wrong

  • B. `netstat` shows network connections and listening ports, not hidden processes.
  • C. `top` provides a real-time view of running processes but relies on standard system interfaces and would be bypassed by a rootkit designed to hide processes.
  • D. `lsof` (list open files) shows open files and the processes using them but doesn't specifically detect hidden processes at the kernel level.

Rootkit Detection Tools

Specialized utilities designed to identify the presence of rootkits on a system by looking for anomalies in system calls, hidden files, processes, or network connections.

  • Bypasses standard OS tools.
  • Checks for kernel-level manipulations.
  • Examples: `chkrootkit`, `rkhunter`.

Memory trick: To find a hidden rootkit, you need a special 'checker', not just the 'standard' process or file views.

More Host-Based Analysis questions