CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A security analyst is investigating a suspected intrusion. They find evidence that an attacker gained initial access through a phishing email and then used a known operating system vulnerability to elevate privileges. The attacker then used these elevated privileges to deploy a backdoor and establish a command-and-control channel. Which MITRE ATT&CK tactic does the deployment of the backdoor and establishment of the C2 channel primarily represent?

  1. AInitial Access
  2. BPrivilege Escalation
  3. CPersistence
  4. DDiscovery
Show answer & explanation

Correct answer: C. Persistence

The deployment of a backdoor and establishment of a command-and-control channel after initial access and privilege escalation are classic examples of the 'Persistence' tactic within MITRE ATT&CK. This tactic focuses on techniques that adversaries use to maintain their foothold on systems across restarts, changes in credentials, and other interruptions.

Why the other options are wrong

  • A. Initial Access is how the attacker gains their first foothold, which was the phishing email.
  • B. Privilege Escalation is the act of gaining higher-level permissions, which happened after initial access.
  • D. Discovery involves techniques for an adversary to gain knowledge about the system and internal network.

MITRE ATT&CK: Persistence

Adversary techniques that enable them to maintain their foothold on a system, even after restarts, changes in credentials, or other interruptions.

  • Aims to ensure continued access to the compromised system.
  • Examples include backdoors, startup items, scheduled tasks, and C2 channels.
  • Often follows initial access and privilege escalation.

Memory trick: Initial, Execute, Persist, Privilege, Defend, Creds, Discover, Lateral, Collect, Command, Exfil, Impact – The attacker's full playbook!

More Vulnerability Management questions