After gaining initial access to a host, which technique would a tester use to maintain access across reboots, ensuring their foothold persists even if the initial exploited service is restarted?
Correct Answer: Establishing persistence, such as creating a scheduled task, service, or registry run key that re-executes the implant
Explanation: Establishing persistence, such as creating a scheduled task, malicious service, or registry run key that re-executes the implant, ensures the tester's foothold survives a reboot or the closure of the initially exploited process, maintaining access for the remainder of the engagement.
Correct Answer: Establishing persistence, such as creating a scheduled task, service, or registry run key that re-executes the implant
Explanation: Establishing persistence, such as creating a scheduled task, malicious service, or registry run key that re-executes the implant, ensures the tester's foothold survives a reboot or the closure of the initially exploited process, maintaining access for the remainder of the engagement.
Correct Answer: Establishing persistence, such as creating a scheduled task, service, or registry run key that re-executes the implant
Explanation: Establishing persistence, such as creating a scheduled task, malicious service, or registry run key that re-executes the implant, ensures the tester's foothold survives a reboot or the closure of the initially exploited process, maintaining access for the remainder of the engagement.