CompTIA SecurityX (CAS-005)Security OperationsEasy

A security analyst is investigating a suspected data breach involving sensitive customer information. The forensic investigation reveals that an attacker gained access through a vulnerable web application, escalated privileges, and then maintained persistence by injecting malicious code into a legitimate system process that restarts automatically. Which of the following MITRE ATT&CK tactics does this persistence method MOST directly align with?

  1. AInitial Access
  2. BPersistence
  3. CDefense Evasion
  4. DExecution
Show answer & explanation

Correct answer: B. Persistence

Injecting malicious code into a legitimate system process that restarts automatically is a classic method for maintaining persistence on a compromised system. This ensures the attacker retains access even after reboots or system resets, directly aligning with the 'Persistence' tactic in MITRE ATT&CK.

Why the other options are wrong

  • A. Initial Access refers to how adversaries gain their first foothold in a network, not how they maintain it.
  • C. Defense Evasion involves techniques to avoid detection, which can be part of persistence but is not the primary goal of injecting code for automatic restarts.
  • D. Execution refers to running adversary-controlled code on a local or remote system, but not specifically the method of maintaining access over time.

MITRE ATT&CK Persistence

The MITRE ATT&CK 'Persistence' tactic describes techniques adversaries use to maintain their foothold in a system across reboots, changes in credentials, or other interruptions.

  • Ensures continued access to a compromised system.
  • Often involves modifying system startup mechanisms, creating new user accounts, or injecting code.
  • Crucial for long-term operations by an attacker.

Memory trick: Initial Execution Persists to Evade Credentials.

More Security Operations questions