QuestionQ26

Threat Hunting Techniques

A security analyst suspects, based on the telemetry observed so far, that the latest attack on a company machine is memory-resident.

Which action must the analyst take next to confirm this suspicion?

Explanation

Memory-resident malware exists in volatile system memory, so acquiring a memory dump before rebooting or otherwise altering the host preserves the evidence needed to identify malicious processes, injected code, and other in-memory artifacts. Memory dumps can be analyzed with forensic/debugging tools such as WinDbg.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!