What will a threat actor do to create a back door on a compromised target according to the Cyber Kill Chain model?Add services and autorun keys.Open a two-way communications channel to the CnC infrastructure.Obtain an automated tool to deliver the malware payload.Collect and exfiltrate data.Navigation Bar
Question
What will a threat actor do to create a back door on a compromised target according to the Cyber Kill Chain model?Add services and autorun keys.Open a two-way communications channel to the CnC infrastructure.Obtain an automated tool to deliver the malware payload.Collect and exfiltrate data.Navigation Bar
Solution
The Cyber Kill Chain model is a sequence of steps that trace stages of a cyberattack from the early reconnaissance stages to the exfiltration of data. The steps you mentioned seem to be out of order. Here's how a threat actor would typically create a backdoor on a compromised target according to the Cyber Kill Chain model:
-
Reconnaissance: The threat actor first identifies the target and gathers as much information as possible about it. This could involve understanding the target's vulnerabilities, which could be exploited later.
-
Weaponization: The threat actor creates a malware payload that can exploit the vulnerabilities identified in the previous step. This could be a virus, worm, or any other type of malicious software.
-
Delivery: The threat actor delivers the malware to the target. This could be done through various methods such as email attachments, malicious downloads, or infected USB drives.
-
Exploitation: The malware exploits the identified vulnerability to create a breach in the target's security. This could involve running malicious code that takes advantage of the vulnerability.
-
Installation: The malware installs a backdoor on the target. This could involve adding services and autorun keys to ensure that the backdoor remains even if the system is rebooted.
-
Command and Control (CnC): The malware opens a two-way communication channel to the CnC infrastructure. This allows the threat actor to control the target remotely.
-
Actions on Objectives: The threat actor can now carry out their intended actions, such as collecting and exfiltrating data.
So, to create a backdoor on a compromised target, a threat actor would typically identify a vulnerability (Reconnaissance), create a malware payload (Weaponization), deliver the malware to the target (Delivery), exploit the vulnerability (Exploitation), install the backdoor (Installation), establish a connection to their CnC infrastructure (Command and Control), and finally carry out their intended actions (Actions on Objectives).
Similar Questions
When dealing with security threats and using the Cyber Kill Chain model, which two approaches can an organization use to block a potential back door creation? (Choose two.)Use HIPS to alert or place a block on common installation paths.Consolidate the number of Internet points of presence.Conduct damage assessment.Audit endpoints to discover abnormal file creations.Establish an incident response playbook.
According to the Cyber Kill Chain model, after a weapon is delivered to a targeted system, what is the next step that a threat actor would take?weaponizationinstallationaction on objectivesexploitation
What is the last stage of the Cyber Kill Chain framework?Question 2Select one:creation of malicious payloadgathering target informationremote control of the target devicemalicious action
A threat actor collects information from web servers of an organization and searches for employee contact information. The information collected is further used to search personal information on the Internet. To which attack phase do these activities belong according to the Cyber Kill Chain model?weaponizationreconnaissanceaction on objectivesexploitationNavigation Bar
Which technique is NOT used to break the command and control – CnC - phase of the Cyber Kill Chain®?1 pointBlocking outbound traffic to known malicious sites and IP addressesDNS sinkholingVulnerability and Patch ManagementDNS poisoning
Upgrade your grade with Knowee
Get personalized homework help. Review tough concepts in more detail, or go deeper into your topic by exploring other relevant questions.