Soru

Zorluk: OrtaMalware Types and Indicators of Compromise

During a security assessment of a critical server, anomalous network connections are observed originating from a system process. Standard endpoint detection tools running on the native operating system report no suspicious processes or modified system binaries. However, when inspecting the host via an offline forensic image, an unauthorized kernel driver is discovered that hooks system calls to hide its running processes and network sockets from native operating system APIs. Which of the following malware types best describes this behavior?

  1. RootkitCevap
  2. B
    Trojan
  3. C
    Worm
  4. D
    Logic Bomb

Cevap

Rootkit
The correct answer is Rootkit because rootkits operate at a deep system level (often kernel-mode) and modify or hook operating system API calls, effectively cloaking processes, open ports, and files from local administration and antivirus utilities.

Adım Adım Çözüm

1
Analyze the observed indicators of compromise
Identified anomalous network traffic that is invisible to security monitoring software running within the active host operating system.
Security tools relying on native OS APIs fail to detect the process because the underlying system calls are manipulated.
2
Evaluate the forensic evidence from offline disk image analysis
Discovered an unauthorized kernel driver hooking system calls to conceal active processes and open sockets.
Operating at the kernel layer to intercept API requests and cloak system artifacts is the primary capability of rootkit malware.
3
Map technical findings to standard malware categories
Conclude that the behavioral telemetry aligns with a kernel-mode rootkit.
Rootkits maintain persistent, privileged access while actively hiding their components from native system administration utilities.

Anahtar Kavram

Rootkits subvert operating system integrity by hooking API calls and kernel structures to conceal files, processes, and network connections from detection tools.
Bu soruyu puanla