CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard
A penetration tester has successfully gained access to a Windows server within a client's internal network. During the post-exploitation phase, the tester aims to maintain persistent access. Which of the following methods, when implemented, would provide the MOST covert and resilient form of persistence?
- AInjecting a malicious DLL into a legitimate system process that re-establishes C2.
- BEstablishing a scheduled task that executes a reverse shell payload every hour.
- CCreating a new administrator account with a generic username and password.
- DModifying the 'Run' registry key to launch a backdoor upon user login.
Show answer & explanationAnswer & explanation
Correct answer: A. Injecting a malicious DLL into a legitimate system process that re-establishes C2.
Injecting a malicious DLL into a legitimate system process is highly covert as it blends with normal operations and is resilient because it can be re-established even if the initial process is terminated. It's less likely to be detected by standard monitoring tools compared to other methods.
Why the other options are wrong
- B. Scheduled tasks are often scrutinized by system administrators and security tools, making them less covert and resilient.
- C. Creating a new administrator account is easily detectable through user account auditing and is not covert.
- D. Modifying 'Run' registry keys is a common persistence mechanism that is frequently monitored by Endpoint Detection and Response (EDR) solutions, making it less covert.
DLL Injection for Persistence
A technique to maintain persistence on a compromised system by forcing a legitimate process to load and execute a malicious Dynamic Link Library (DLL).
- Malicious code runs within a trusted process's memory space.
- Difficult to detect as it mimics legitimate system behavior.
- Can re-establish command and control (C2) even if parent process terminates.
Memory trick: Remember, the ghost in the machine links deeply for persistence.