CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A SOC analyst reviewing endpoint logs finds the following command executed by a standard user's process: `C:\Windows\System32\sc.exe config wuauserv binpath= "cmd.exe /c net user backupadmin P@ssw0rd123! /add" start= auto` The attacker then restarts the Windows Update service to trigger the command with SYSTEM-level rights. Which MITRE ATT&CK tactic does this behavior represent?

  1. APrivilege Escalation
  2. BExfiltration
  3. CDiscovery
  4. DPersistence
Show answer & explanation

Correct answer: A. Privilege Escalation

Reconfiguring a service's binary path to run attacker-controlled commands under SYSTEM privileges, then triggering that service, is a classic Privilege Escalation technique used to elevate from a standard user to SYSTEM-level access.

Why the other options are wrong

  • B. Exfiltration involves moving stolen data out of the network, unrelated to this command.
  • C. Discovery involves enumerating system/network information, not modifying service configuration for elevated execution.
  • D. Persistence would involve maintaining access across reboots (e.g., a scheduled task), not elevating privileges.

MITRE ATT&CK: Privilege Escalation

A tactic covering techniques adversaries use to gain higher-level permissions on a system or network, such as abusing services that run with elevated privileges.

  • Includes techniques like Service Manipulation, Access Token Manipulation, Exploitation for Privilege Escalation
  • Often follows Initial Access/Execution
  • Enables attackers to bypass restrictions imposed by lower-privileged accounts

Memory trick: Sc.exe service hijack = climbing the SYSTEM ladder.

More Vulnerability Management questions