A penetration tester is conducting a post-exploitation phase on a Windows server. They have successfully established a privileged shell and now want to ensure their access persists even if the server reboots or their initial exploit path is closed. Which of the following techniques would be most effective for establishing a persistent backdoor without immediately triggering common antivirus alerts?
- AModifying the `boot.ini` file to load a custom kernel module.
- BScheduling a new task using `cron` to run a reverse shell periodically.
- CCreating a new service with an automatic startup type that executes a malicious payload.
- DInjecting a DLL into a critical system process like `lsass.exe`.
Show answer & explanationAnswer & explanation
Correct answer: C. Creating a new service with an automatic startup type that executes a malicious payload.
Creating a new service configured for automatic startup is a common and effective method for establishing persistence on Windows systems. Services run in the background, often with elevated privileges, and are designed to start automatically with the system, making them resilient to reboots. This method is less likely to be immediately flagged by standard antivirus compared to injecting into critical processes or modifying boot files directly.
Why the other options are wrong
- A. Modifying `boot.ini` (or more modern equivalents like BCD) is a highly intrusive action, likely to cause system instability or be detected by boot integrity checks and advanced endpoint protection tools.
- B. `cron` is a scheduling utility for Unix-like operating systems (Linux, macOS), not Windows. Windows uses Task Scheduler for similar functionality.
- D. Injecting into `lsass.exe` is a high-risk operation, often associated with credential dumping and is frequently monitored by EDR/AV solutions, making it prone to detection for persistence.
Windows Service Persistence
Establishing a persistent backdoor on a Windows system by creating or modifying a legitimate service to execute malicious code, ensuring it runs automatically upon system startup.
- Services run in the background, often with SYSTEM privileges.
- They are designed to start automatically with the operating system.
- Can be created using tools like `sc.exe` or `New-Service` in PowerShell.
- Difficult to detect without specific monitoring of service creation/modification.
Memory trick: Windows attackers love services, startups, and scheduled tasks to stay hidden.