QuestionQ54

Incident Response and Management

An incident-response analyst is investigating the root cause of a recent malware outbreak. Initial binary analysis indicates that the malware disables host security services and performs cleanup routines on infected hosts, including deletion of the initial dropper and removal of event-log entries and prefetch files from the host. Which of the following data sources would most likely reveal evidence of the root cause?

Choose two
Explanation

Registry artifacts survive this malware's cleanup routine: the keys and values changed to disable host security services remain, along with persistence entries such as Run keys and service definitions and execution-tracking hives like Amcache and Shimcache, which record binaries that ran even after those binaries and their prefetch entries are gone. EDR telemetry is the other surviving source, because the sensor streams behavioral data off the endpoint and retains it centrally, so process lineage, file writes, and network connections captured before the agent was tampered with still show how the dropper arrived and what executed it, which is precisely the root cause being sought. The dropper file and its timestamps were deleted, prefetch files were removed, and Sysmon writes into the Windows event-log subsystem that the malware purged, so none of those sources can be relied on in this scenario.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!