Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium
A security analyst is investigating a series of alerts from a host-based intrusion detection system (HIDS) indicating 'Registry Key Modification: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'. The alerts show that a new entry has been added pointing to an executable in the C:\Users\Public\ directory. What is the most likely purpose of this registry modification?
- ATo elevate user privileges
- BTo disable system services
- CTo establish persistence
- DTo delete critical system files
Show answer & explanationAnswer & explanation
Correct answer: C. To establish persistence
The 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' registry key is a well-known location where programs can register themselves to automatically start when Windows boots up or a user logs in. Adding an entry here is a common technique used by malware to ensure it restarts and maintains its presence on the system after a reboot, which is known as establishing persistence.
Why the other options are wrong
- A. Privilege elevation typically involves exploiting vulnerabilities or misconfigurations, not directly adding an entry to the 'Run' key, although a persistent malware might later attempt privilege escalation.
- B. Disabling system services usually involves modifying specific service keys or using tools like 'sc' command, not adding entries to the 'Run' key.
- D. Deleting critical system files would be a destructive action, not an action facilitated by adding an entry to the 'Run' key, which is for program execution.
Persistence Mechanisms
Techniques used by attackers to maintain access to a compromised system across reboots, loss of network connectivity, or credential changes.
- Ensures malware or attacker tools restart automatically.
- Common methods include registry run keys, startup folders, scheduled tasks, and services.
- Crucial for long-term compromise and covert operations.
Memory trick: After the initial breach, the attacker wants to stay, like a persistent guest.