Today’s SY0-701 CompTIA Security+ Pop Quiz: I didn’t see you there

A security analyst is investigating a workstation where a legitimate system process is performing unauthorized network connections. No new or suspicious executable files were found in the process list. Which technique is the attacker likely using to hide this malicious activity within the trusted application?