CompTIA CySA+ (CS0-003)Vulnerability ManagementHard
During incident triage, an analyst finds the following command run from an already-compromised workstation: `C:\Windows\System32> psexec.exe \\FIN-SRV02 -u CORP\svc_backup -p ******** cmd.exe /c whoami` The command successfully authenticates to a second, previously unaffected server and runs a command remotely. Which MITRE ATT&CK tactic does this action represent?
- ACollection
- BInitial Access
- CCommand and Control
- DLateral Movement
Show answer & explanationAnswer & explanation
Correct answer: D. Lateral Movement
Using PsExec with stolen credentials to remotely execute commands on another internal server is a classic Lateral Movement technique (T1021.002, Remote Services: SMB/Windows Admin Shares), allowing the adversary to pivot from the initially compromised workstation to additional systems within the network.
Why the other options are wrong
- A. Collection involves gathering data of interest, not moving between systems.
- B. Initial Access refers to the first foothold gained in the environment, which already occurred on the workstation.
- C. Command and Control refers to communication with external attacker infrastructure, not internal pivoting.
MITRE ATT&CK: Lateral Movement
A tactic covering techniques adversaries use to move through a network from an initial foothold to additional systems, often using legitimate administrative tools and stolen credentials, such as PsExec, WMI, or RDP.
- T1021.002: Remote Services (SMB/Windows Admin Shares) commonly implemented via PsExec
- Relies on valid or stolen credentials to blend in with normal admin activity
- Detected via monitoring unusual admin-share/service creation across hosts
Memory trick: PsExec is the attacker's stolen master key, unlocking one office door after another.