CompTIA SecurityX (CAS-005)Security OperationsMedium

A security team is developing a threat hunting hypothesis: 'Adversaries are using legitimate administrative tools (LOLBins) to move laterally within our network, specifically targeting RDP sessions.' Which of the following data sources would be most critical to analyze to validate this hypothesis?

  1. AWeb application firewall (WAF) logs for SQL injection attempts.
  2. BEndpoint Detection and Response (EDR) telemetry for process execution and network connections.
  3. CDNS server logs for unusual domain lookups.
  4. DCloud access security broker (CASB) logs for unauthorized cloud resource access.
Show answer & explanation

Correct answer: B. Endpoint Detection and Response (EDR) telemetry for process execution and network connections.

The hypothesis focuses on 'legitimate administrative tools (LOLBins)' and 'lateral movement... targeting RDP sessions'. EDR telemetry provides granular visibility into process execution (to identify LOLBins), network connections (to see RDP traffic), and parent-child process relationships, making it ideal for detecting and analyzing lateral movement and LOLBin usage on endpoints.

Why the other options are wrong

  • A. WAF logs are for web application attacks and won't show internal lateral movement or LOLBin usage.
  • C. DNS logs help with C2 or initial reconnaissance, but not directly with LOLBin execution or RDP lateral movement.
  • D. CASB logs focus on cloud access, not internal network lateral movement on endpoints.

EDR for Lateral Movement

Endpoint Detection and Response (EDR) solutions collect and analyze endpoint data (process execution, network connections, file system changes) to detect, investigate, and respond to threats like lateral movement and LOLBin abuse.

  • Provides granular endpoint visibility.
  • Detects anomalous process behavior.
  • Tracks network connections originating from endpoints.
  • Essential for post-compromise detection.

Memory trick: To find the thief, you need to look at the footprints they left.

More Security Operations questions