A threat hunter wants to detect fileless malware activity using Cisco Secure Endpoint. Which behavior would MOST strongly indicate fileless execution?
The correct answer is legitimate system processes executing encoded commands. Fileless malware avoids writing binaries to disk and instead abuses trusted processes such as PowerShell, WMI, or rundll32.
Encoded or obfuscated commands executed by legitimate binaries are a strong indicator of fileless execution and defense evasion. Cisco Secure Endpoint provides deep visibility into command-line arguments and process behavior, enabling detection of this technique.
Option A is normal behavior. Option B may indicate suspicious execution but still involves files. Option D relies on file presence, which fileless attacks intentionally avoid.
This technique aligns with MITRE ATT&CK -- Command and Scripting Interpreter and Defense Evasion and is directly relevant to CBRTHD exam objectives related to endpoint-based threat hunting.
Therefore, Option C is the correct answer.
Wilda
3 days agoSylvie
8 days agoBrinda
13 days agoMarguerita
19 days agoRyann
24 days agoRozella
29 days agoTwila
1 month agoJoana
1 month agoMaile
1 month agoMertie
2 months agoLorrine
2 months agoBrice
2 months agoOctavio
2 months agoStephanie
2 months agoTyra
4 months ago