An incident responder identifies a suspicious PowerShell process executing encoded commands on an enterprise server. To effectively contain the host while preserving volatile evidence for forensic analysis, which action should the responder prioritize?
Trap 1: Immediately disconnect the network cable to prevent further C2…
Disconnecting the network cable effectively stops C2 traffic but destroys all volatile data currently residing in RAM. This approach results in the loss of critical artifacts such as decrypted malicious payloads, resident memory-only malware, and active session tokens which are essential for conducting a comprehensive forensic root cause analysis.
Trap 2: Perform a remote shutdown of the host to ensure the system is in a…
Shutting down the host triggers the OS to clear page files and volatile memory buffers, permanently destroying evidence of the malicious process. Forensic best practices dictate that volatile memory must be captured using a trusted, statically linked tool before any system state changes occur, as shutdown processes wipe critical forensic artifacts.
Trap 3: Update the host's antivirus signature and run a full system scan.
Running an antivirus scan alters the file system metadata and changes memory state, potentially corrupting forensic evidence. Furthermore, sophisticated malware often uses anti-forensic techniques to detect scan activity and terminate or obfuscate its presence, rendering the resulting scan report unreliable for an incident response investigation and forensic reconstruction.
- A
Immediately disconnect the network cable to prevent further C2 communication.
Why it fails: Disconnecting the network cable effectively stops C2 traffic but destroys all volatile data currently residing in RAM. This approach results in the loss of critical artifacts such as decrypted malicious payloads, resident memory-only malware, and active session tokens which are essential for conducting a comprehensive forensic root cause analysis.
- B
Perform a remote shutdown of the host to ensure the system is in a known safe state.
Why it fails: Shutting down the host triggers the OS to clear page files and volatile memory buffers, permanently destroying evidence of the malicious process. Forensic best practices dictate that volatile memory must be captured using a trusted, statically linked tool before any system state changes occur, as shutdown processes wipe critical forensic artifacts.
- C
Capture a memory image using a trusted forensic tool before isolating the machine.
Capturing memory first preserves the state of the machine, including the running malicious processes and their decrypted command-line arguments. This aligns with the Order of Volatility, ensuring that the most ephemeral and valuable data is collected before containment actions like network isolation or system shutdown are performed by the responder.
- D
Update the host's antivirus signature and run a full system scan.
Why it fails: Running an antivirus scan alters the file system metadata and changes memory state, potentially corrupting forensic evidence. Furthermore, sophisticated malware often uses anti-forensic techniques to detect scan activity and terminate or obfuscate its presence, rendering the resulting scan report unreliable for an incident response investigation and forensic reconstruction.