3C. Analyse endpoint monitoring output obj 3.1, 3.2 Flashcards

1
Q

EPP

A

Endpoint Protection Platform
- a single agent that performs multiple security tasks (e.g., host firewall, malware detection). Used as a means of preventing performance issues caused by running multiple security products
- Signature-based

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

EDR

A

Endpoint Detection and Response
- uses behavioural and anomaly-based analysis to provide real-time insights into a compromise
- containment and remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

UEBA

A

User and Entity Behaviour Analytics
- provides analysis process for identifying malicous activity by establishing a baseline behaviour for entities (e.g., workstation) and detecting deviations from this behaviour

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Typical malware attack stages

A

1) Dropper/downloader
2) Maintain access
3) Strengthen access
4) Actions on Objectives
5) Concealment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Methods for performing Code Injection

A

1) Masquerading
- dropper replaces genuine executable with malicious one

2) DLL injection
- dropper forces the process to load a DLL, which then executes malicious code

3) DLL side loading
- dropper exploits vuln in program’s manifest to load a malicious DLL at runtime

4) Process Hollowing
- dropper starts process in suspended state, rewrites memory locations containing process code with the malware code

How well did you know this?
1
Not at all
2
3
4
5
Perfectly