During a post-incident security review of a critical enterprise server, system logs indicate that disk-based malware scanners and host integrity checks reported zero altered binaries or suspicious files on the file system. However, memory analysis reveals unauthorized code executing during early system initialization, hijacking the Volume Boot Record (VBR) execution path before the core operating system kernel load and security controls initialize. Which malware classification is directly indicated by this persistence and execution behavior?
- BootkitCevap
- BLogic Bomb
- CRemote Access Trojan
- DSelf-Propagating Worm
Cevap
Bootkit
A bootkit targets the early boot sequence (such as the MBR, VBR, or UEFI execution flow), granting execution control before the OS kernel and host security scanners load.
Adım Adım Çözüm
Anahtar Kavram
Bootkit Malware and Pre-Boot Indicators of Compromise