The SOC receives an alert from a network sensor showing an internal host communicating with a known malicious IP over HTTPS. The analyst cannot find any process making outbound connections on the host. What should the analyst do next?
A malicious outbound HTTPS connection with no visible owning process indicates the connection is hidden from standard process enumeration, typical of rootkit or kernel-level concealment. Specialised tools such as memory or kernel inspection utilities can reveal hidden processes that Task Manager or netstat alone would miss.
Why this answer
The absence of a visible process making outbound connections suggests the presence of a rootkit or hidden process that evades standard detection. Using specialized tools to check for hidden processes or rootkits is the appropriate next step to identify the malicious activity before taking containment or remediation actions.