CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A SOC analyst reviewing endpoint logs finds the following command executed by a standard user's process: `C:\Windows\System32\sc.exe config wuauserv binpath= "cmd.exe /c net user backupadmin P@ssw0rd123! /add" start= auto` The attacker then restarts the Windows Update service to trigger the command with SYSTEM-level rights. Which MITRE ATT&CK tactic does this behavior represent?
- APrivilege Escalation
- BExfiltration
- CDiscovery
- DPersistence
Show answer & explanationAnswer & explanation
Correct answer: A. Privilege Escalation
Reconfiguring a service's binary path to run attacker-controlled commands under SYSTEM privileges, then triggering that service, is a classic Privilege Escalation technique used to elevate from a standard user to SYSTEM-level access.
Why the other options are wrong
- B. Exfiltration involves moving stolen data out of the network, unrelated to this command.
- C. Discovery involves enumerating system/network information, not modifying service configuration for elevated execution.
- D. Persistence would involve maintaining access across reboots (e.g., a scheduled task), not elevating privileges.
MITRE ATT&CK: Privilege Escalation
A tactic covering techniques adversaries use to gain higher-level permissions on a system or network, such as abusing services that run with elevated privileges.
- Includes techniques like Service Manipulation, Access Token Manipulation, Exploitation for Privilege Escalation
- Often follows Initial Access/Execution
- Enables attackers to bypass restrictions imposed by lower-privileged accounts
Memory trick: Sc.exe service hijack = climbing the SYSTEM ladder.