A security analyst is investigating a macOS endpoint that appears to have an unauthorized kernel extension loaded. Which command-line utility should the analyst use to list currently loaded kernel extensions to verify if the extension is properly signed?
Trap 1: sysctl -a
The sysctl command is used to retrieve or modify kernel state variables and system parameters. While it provides deep insight into system settings, it does not provide a list of loaded kernel extensions or their signature status, which is the specific requirement for this investigation scenario.
Trap 2: tmutil list
The tmutil command is the utility used to manage Time Machine backups. It has no functionality related to the kernel, driver loading, or system integrity verification. Using it to investigate kernel extensions would yield no relevant information regarding the security state of the system's loaded drivers.
Trap 3: spctl --list
The spctl command manages the Secure Policy subsystem, which controls Gatekeeper rules and assessment policies. While it helps manage software installation policies, it does not display a list of currently running kernel extensions. Therefore, it is the wrong tool for identifying loaded malicious drivers in the kernel.
- A
kextstat
The kextstat command provides a detailed list of all currently loaded kernel extensions. It is the standard utility for administrators to inspect the system's kernel state, allowing for the identification of third-party extensions that may not be legitimately signed or that exhibit suspicious, unauthorized behavior.
- B
sysctl -a
Why it fails: The sysctl command is used to retrieve or modify kernel state variables and system parameters. While it provides deep insight into system settings, it does not provide a list of loaded kernel extensions or their signature status, which is the specific requirement for this investigation scenario.
- C
tmutil list
Why it fails: The tmutil command is the utility used to manage Time Machine backups. It has no functionality related to the kernel, driver loading, or system integrity verification. Using it to investigate kernel extensions would yield no relevant information regarding the security state of the system's loaded drivers.
- D
spctl --list
Why it fails: The spctl command manages the Secure Policy subsystem, which controls Gatekeeper rules and assessment policies. While it helps manage software installation policies, it does not display a list of currently running kernel extensions. Therefore, it is the wrong tool for identifying loaded malicious drivers in the kernel.