A threat hunter analyzing an infected endpoint finds that malicious processes keep reappearing even after termination, making traditional remediation ineffective. The user of the endpoint reports occasional system slowdowns, abnormal pop-ups, and unauthorized application launches. Upon deeper inspection, the threat hunter discovers that the system has multiple scheduled tasks executing unknown scripts at specific intervals, along with suspicious registry modifications that enable automatic script execution upon startup. Further investigation reveals that the endpoint has made occasional outbound connections to an unclassified external server, though the traffic is encrypted and intermittent. Additionally, the organization recently experienced multiple failed login attempts on privileged accounts originating from the same subnet, raising concerns about potential credential theft or lateral movement. With the possibility of persistence mechanisms, lateral movement, or external C2 activity, which signs should the threat hunter look out for to confirm and mitigate the threat?
Select an option, then click Submit answer.
Reference / correct answer:
Most accepted answer: D. Host-Based Artifacts
Community votes: D=2
Selected Answer: D Host based artifacts upvoted 1 times
Selected Answer: D The scenario strongly emphasizes persistence mechanisms and endpoint-level changes, which are classic host-based artifacts. The threat hunter has already observed several indicators that live directly on the system upvoted 1 times