Question 1
An investigator is analyzing a memory dump from a compromised Linux server that hosted multiple Docker containers. The attacker allegedly used a fileless malware variant that executed entirely in memory. The investigator suspects the malware manipulated system calls using a kernel module. Which Volatility 3 plugin would be most effective for initially identifying anomalous kernel modules and their hooks?
Answer and explanation
Correct answer: C
The linux_check_syscall plugin is specifically designed to check the system call table for hooks, which is a common technique used by rootkits and fileless malware to intercept and manipulate system functions. While linux_pslist shows processes and linux_lsmod lists loaded modules, linux_check_syscall directly addresses the suspected manipulation of system calls, making it the most effective initial step. linux_check_creds is used for checking process credentials for signs of privilege escalation.