CompTIA CySA+ (CS0-003)Security OperationsMedium

A security analyst is reviewing alerts from an EDR solution. An alert indicates that `cmd.exe` spawned `powershell.exe`, which then executed a base64-encoded command. The EDR also reports that `powershell.exe` then made an outbound connection to a suspicious IP address (185.x.x.x) on port 80. The encoded command, when decoded, reveals a script attempting to download and execute a file from the same suspicious IP. Which MITRE ATT&CK technique does this scenario primarily represent?

  1. AT1036.003 - Rename System Utilities
  2. BT1059.001 - PowerShell
  3. CT1071.001 - Web Protocols
  4. DT1105 - Ingress Tool Transfer
Show answer & explanation

Correct answer: D. T1105 - Ingress Tool Transfer

The scenario describes `powershell.exe` downloading and executing a file from an external IP. This directly aligns with T1105 Ingress Tool Transfer, which involves transferring tools or files from an external system to a compromised host. While PowerShell (T1059.001) and Web Protocols (T1071.001) are involved, the primary action of downloading the file is T1105.

Why the other options are wrong

  • A. T1036.003 (Rename System Utilities) involves masquerading by renaming legitimate utilities, which is not described in this scenario.
  • B. T1059.001 (PowerShell) describes the use of PowerShell for execution, which is present, but it's a sub-technique of command and scripting interpreter, not the primary action of bringing in a tool.
  • C. T1071.001 (Web Protocols) describes using HTTP/S for C2, which is part of the communication, but the core action of bringing a file in is more specific to T1105.

Ingress Tool Transfer (T1105)

Ingress Tool Transfer (MITRE ATT&CK T1105) describes the adversary's capability to transfer tools or files from an external system into a compromised environment. This is often done to introduce additional malware, utilities, or scripts required for further attack phases.

  • Involves bringing files from outside to inside the network.
  • Commonly uses HTTP/HTTPS, FTP, or other protocols.
  • Often follows initial access and enables further exploitation or persistence.

Memory trick: Attackers follow a map to reach their treasure.

More Security Operations questions