CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A security analyst is investigating a suspected intrusion. They find evidence that an attacker gained initial access through a phishing email and then used a known operating system vulnerability to elevate privileges. The attacker then used these elevated privileges to deploy a backdoor and establish a command-and-control channel. Which MITRE ATT&CK tactic does the deployment of the backdoor and establishment of the C2 channel primarily represent?
- AInitial Access
- BPrivilege Escalation
- CPersistence
- DDiscovery
Show answer & explanationAnswer & explanation
Correct answer: C. Persistence
The deployment of a backdoor and establishment of a command-and-control channel after initial access and privilege escalation are classic examples of the 'Persistence' tactic within MITRE ATT&CK. This tactic focuses on techniques that adversaries use to maintain their foothold on systems across restarts, changes in credentials, and other interruptions.
Why the other options are wrong
- A. Initial Access is how the attacker gains their first foothold, which was the phishing email.
- B. Privilege Escalation is the act of gaining higher-level permissions, which happened after initial access.
- D. Discovery involves techniques for an adversary to gain knowledge about the system and internal network.
MITRE ATT&CK: Persistence
Adversary techniques that enable them to maintain their foothold on a system, even after restarts, changes in credentials, or other interruptions.
- Aims to ensure continued access to the compromised system.
- Examples include backdoors, startup items, scheduled tasks, and C2 channels.
- Often follows initial access and privilege escalation.
Memory trick: Initial, Execute, Persist, Privilege, Defend, Creds, Discover, Lateral, Collect, Command, Exfil, Impact – The attacker's full playbook!