Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium

A security analyst is investigating a series of alerts from a host-based intrusion detection system (HIDS) indicating 'Registry Key Modification: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'. The alerts show that a new entry has been added pointing to an executable in the C:\Users\Public\ directory. What is the most likely purpose of this registry modification?

  1. ATo elevate user privileges
  2. BTo disable system services
  3. CTo establish persistence
  4. DTo delete critical system files
Show answer & explanation

Correct answer: C. To establish persistence

The 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' registry key is a well-known location where programs can register themselves to automatically start when Windows boots up or a user logs in. Adding an entry here is a common technique used by malware to ensure it restarts and maintains its presence on the system after a reboot, which is known as establishing persistence.

Why the other options are wrong

  • A. Privilege elevation typically involves exploiting vulnerabilities or misconfigurations, not directly adding an entry to the 'Run' key, although a persistent malware might later attempt privilege escalation.
  • B. Disabling system services usually involves modifying specific service keys or using tools like 'sc' command, not adding entries to the 'Run' key.
  • D. Deleting critical system files would be a destructive action, not an action facilitated by adding an entry to the 'Run' key, which is for program execution.

Persistence Mechanisms

Techniques used by attackers to maintain access to a compromised system across reboots, loss of network connectivity, or credential changes.

  • Ensures malware or attacker tools restart automatically.
  • Common methods include registry run keys, startup folders, scheduled tasks, and services.
  • Crucial for long-term compromise and covert operations.

Memory trick: After the initial breach, the attacker wants to stay, like a persistent guest.

More Security Monitoring questions