CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A SOC analyst investigating a compromised workstation finds the following command in the Windows event log: `reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Updater /t REG_SZ /d "C:\Users\Public\svc.exe"` This command runs automatically at every user logon. Which MITRE ATT&CK tactic best describes this behavior?
- APersistence
- BDefense Evasion
- CPrivilege Escalation
- DExecution
Show answer & explanationAnswer & explanation
Correct answer: A. Persistence
Adding an executable to a Registry Run key so it launches automatically at every logon is a classic Persistence technique (T1547.001, Boot or Logon Autostart Execution), ensuring the attacker's access survives reboots and logoffs. It is not, by itself, escalating privileges, hiding from detection, or the initial execution event.
Why the other options are wrong
- B. No evasion technique like obfuscation or process injection is shown here.
- C. The command does not grant higher privileges, only re-launches the payload.
- D. Execution refers to running code initially; this command ensures future re-execution, which is Persistence.
MITRE ATT&CK: Persistence
A tactic covering techniques adversaries use to maintain access to systems across restarts, credential changes, and other interruptions, such as Registry Run keys, scheduled tasks, or startup folder entries.
- T1547.001: Registry Run Keys / Startup Folder is a common sub-technique
- Persistence ensures malware survives reboot or logoff
- Detected via monitoring Registry/startup location changes
Memory trick: Run key = a sticky note that reminds Windows to relaunch the malware every morning.