CompTIA CySA+ (CS0-003)Security OperationsMedium
A security analyst is reviewing alerts from an EDR solution. An alert indicates that `cmd.exe` spawned `powershell.exe`, which then executed a base64-encoded command. The EDR also reports that `powershell.exe` then made an outbound connection to a suspicious IP address (185.x.x.x) on port 80. The encoded command, when decoded, reveals a script attempting to download and execute a file from the same suspicious IP. Which MITRE ATT&CK technique does this scenario primarily represent?
- AT1036.003 - Rename System Utilities
- BT1059.001 - PowerShell
- CT1071.001 - Web Protocols
- DT1105 - Ingress Tool Transfer
Show answer & explanationAnswer & explanation
Correct answer: D. T1105 - Ingress Tool Transfer
The scenario describes `powershell.exe` downloading and executing a file from an external IP. This directly aligns with T1105 Ingress Tool Transfer, which involves transferring tools or files from an external system to a compromised host. While PowerShell (T1059.001) and Web Protocols (T1071.001) are involved, the primary action of downloading the file is T1105.
Why the other options are wrong
- A. T1036.003 (Rename System Utilities) involves masquerading by renaming legitimate utilities, which is not described in this scenario.
- B. T1059.001 (PowerShell) describes the use of PowerShell for execution, which is present, but it's a sub-technique of command and scripting interpreter, not the primary action of bringing in a tool.
- C. T1071.001 (Web Protocols) describes using HTTP/S for C2, which is part of the communication, but the core action of bringing a file in is more specific to T1105.
Ingress Tool Transfer (T1105)
Ingress Tool Transfer (MITRE ATT&CK T1105) describes the adversary's capability to transfer tools or files from an external system into a compromised environment. This is often done to introduce additional malware, utilities, or scripts required for further attack phases.
- Involves bringing files from outside to inside the network.
- Commonly uses HTTP/HTTPS, FTP, or other protocols.
- Often follows initial access and enables further exploitation or persistence.
Memory trick: Attackers follow a map to reach their treasure.