CompTIA SecurityX (CAS-005)Security OperationsEasy
A security analyst is investigating a suspected data breach involving sensitive customer information. The forensic investigation reveals that an attacker gained access through a vulnerable web application, escalated privileges, and then maintained persistence by injecting malicious code into a legitimate system process that restarts automatically. Which of the following MITRE ATT&CK tactics does this persistence method MOST directly align with?
- AInitial Access
- BPersistence
- CDefense Evasion
- DExecution
Show answer & explanationAnswer & explanation
Correct answer: B. Persistence
Injecting malicious code into a legitimate system process that restarts automatically is a classic method for maintaining persistence on a compromised system. This ensures the attacker retains access even after reboots or system resets, directly aligning with the 'Persistence' tactic in MITRE ATT&CK.
Why the other options are wrong
- A. Initial Access refers to how adversaries gain their first foothold in a network, not how they maintain it.
- C. Defense Evasion involves techniques to avoid detection, which can be part of persistence but is not the primary goal of injecting code for automatic restarts.
- D. Execution refers to running adversary-controlled code on a local or remote system, but not specifically the method of maintaining access over time.
MITRE ATT&CK Persistence
The MITRE ATT&CK 'Persistence' tactic describes techniques adversaries use to maintain their foothold in a system across reboots, changes in credentials, or other interruptions.
- Ensures continued access to a compromised system.
- Often involves modifying system startup mechanisms, creating new user accounts, or injecting code.
- Crucial for long-term operations by an attacker.
Memory trick: Initial Execution Persists to Evade Credentials.