L26
Botnets, C2 and malware categories
Cram this first — memory hook
Virus rides; worm walks itself; Trojan disguises; Command and Control directs the group.
Exam trap
Potentially Unwanted Programs/Applications are explicitly excluded even though they appear in the PDF. Advanced Persistent Threat , Advanced Volatile Threat and Low-Observable Characteristics are slide-supported supporting vocabulary, not proof of an exam question.
The slide facts
A botnet consists of infected devices receiving attacker instructions through . Malware coverage names viruses, worms and Trojans, plus advanced persistent/volatile threats and low-observable behavior.
If you have time — extra
A botnet is a group of compromised devices used together. Command and Control (, also written C&C) is the communication/control arrangement used to instruct them; it is not simply a synonym for malware. A virus attaches to a host program or file and commonly needs execution; a worm self-propagates; a Trojan pretends to be legitimate while hiding harmful behavior. Ransomware disrupts access and may steal data; spyware collects information. These latter categories are added explanatory examples rather than the slide's core three-way comparison. Advanced Persistent Threat () describes a sustained, capable campaign, not just one executable. The deck uses Advanced Volatile Threat () for volatile/memory-focused threats and Low-Observable Characteristics () for quiet behavior designed to evade attention. Memory-resident does not mean harmless, impossible to investigate, or permanently removed simply by rebooting. Categories can overlap.
Walkthrough
Recognize suspicious behavior, isolate affected systems under the incident process, preserve relevant evidence, investigate scope and persistence, remove the cause, recover safely and monitor for recurrence.