A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the file in a sandbox and observes that it creates a mutex named 'Global\MyMutex123', attempts to connect to an external IP address on port 443, and modifies the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Which type of analysis is the analyst performing?
Dynamic analysis involves executing malware in a controlled environment, such as a sandbox, and observing its behavior, including process creation, network traffic, and file system changes. The analyst's observations of mutex creation, outbound connections, and registry modification are classic dynamic indicators. This approach reveals runtime actions that static analysis might miss due to obfuscation or packing.
Why this answer
Dynamic analysis is the process of executing malware in a controlled environment and observing its behavior, such as network connections, registry changes, and mutex creation. The analyst's actions in the sandbox directly match this definition. Static analysis, memory forensics, and log analysis do not involve running the sample and monitoring its runtime effects.
Exam trap
The trap here is equating sandbox execution with memory forensics, but memory forensics examines an existing memory image without running the sample.