Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityHard

A security analyst receives an alert from an Endpoint Detection and Response (EDR) system indicating a suspicious process attempting to inject code into another running process on a critical server. This behavior is highly indicative of an advanced persistent threat (APT) attempting to escalate privileges or establish persistence. Which EDR capability is primarily responsible for detecting this type of low-level, in-memory attack technique?

  1. ACloud Sandbox Analysis
  2. BMemory Forensics and Analysis
  3. CNetwork Flow Monitoring
  4. DFile Integrity Monitoring (FIM)
Show answer & explanation

Correct answer: B. Memory Forensics and Analysis

Memory forensics and analysis allows EDR systems to inspect the volatile memory (RAM) of an endpoint. This capability is crucial for detecting sophisticated, fileless malware or in-memory attacks like process injection, where malicious code operates directly in memory without leaving persistent files on the disk, making it invisible to traditional file-based scans.

Why the other options are wrong

  • A. Cloud sandbox analysis executes suspicious files in an isolated environment, but the scenario describes an in-memory attack on a running process, not a file.
  • C. Network flow monitoring analyzes network traffic, not internal process behavior or memory manipulation.
  • D. FIM monitors changes to files, not in-memory process behavior.

Memory Forensics and Analysis

The process of collecting and analyzing data from the volatile memory (RAM) of a computer system to detect signs of malicious activity, such as rootkits, process injection, and other in-memory attacks that do not leave traces on persistent storage.

  • Crucial for detecting fileless malware and advanced persistent threats (APTs).
  • Identifies malicious code or data operating directly within RAM.
  • Requires specialized tools to capture and analyze memory dumps.

Memory trick: To catch the ghost in the machine, you need to look inside its 'thoughts' (memory).

More Endpoint Security questions