Question 1
Q1Multiple answersAn analyst is reviewing logs from a compromised web server to trace lateral movement. They have access to Zeek's conn.log and dce_rpc.log. During the incident window, they observe a successful web shell upload followed by an outbound connection from the web server (192.168.10.5) to a domain controller (192.168.10.10) on TCP port 445. Shortly after, the domain controller makes SMB connections to several other critical servers. Which of the following Zeek log entries would provide the strongest evidence of the specific lateral movement technique used? (Select TWO)
Show answer & explanation
Correct answers: B, D
The atsvc endpoint corresponds to the Task Scheduler service. Attackers commonly use this service remotely (e.g., with at or schtasks) to schedule malicious code execution on a target machine, which is a classic lateral movement technique.
The svcctl endpoint is the Service Control Manager. The CreateServiceW operation indicates that the source host is attempting to create a new service on the destination. This is a very common and powerful lateral movement technique used by tools like PsExec to run code on remote systems.