Soru

Zorluk: OrtaMalware Types and Indicators of Compromise

A threat hunting team performs memory analysis on a suspected workstation and discovers active network sockets associated with hidden execution threads. Lower-level operating system call tables have been intercepted to filter out these specific process IDs from standard administrative monitoring tools. Which of the following malware types is MOST likely operating on the system?

  1. RootkitCevap
  2. B
    Logic bomb
  3. C
    Worm
  4. D
    Trojan

Cevap

Rootkit
The correct answer is the option identifying a rootkit. Rootkits modify core operating system functions, system call tables, or kernel data structures to mask the presence of files, registry keys, network connections, and process listings from standard management utilities.

Adım Adım Çözüm

1
Analyze the technical indicators in the scenario.
Identified system call table interception (API hooking) and intentional hiding of process IDs and active network sockets from user-space administrative tools.
Understanding host telemetry and stealth techniques isolates the fundamental objective of the malware.
2
Compare observed indicators against malware functionality characteristics.
Rootkits operate at deep system levels (kernel or driver level) specifically designed to subvert OS reporting mechanisms and mask unauthorized activities.
Distinguishing stealth/evasion mechanisms from execution or propagation strategies points directly to rootkit functionality.

Anahtar Kavram

Rootkit evasive techniques and kernel-level subversion
Bu soruyu puanla