Which Empire module category provides a way for an agent to survive across logoff or reboot actions by modifying Run Registry keys, logon scripts, or system boot programs?

Study for the SANS560 GIAC Penetration Tester (GPEN) Test. Study with flashcards and multiple choice questions, each question has hints and explanations. Get ready for your exam!

Multiple Choice

Which Empire module category provides a way for an agent to survive across logoff or reboot actions by modifying Run Registry keys, logon scripts, or system boot programs?

Explanation:
Maintaining access after a user logs off or the system reboots is what persistence is all about. In Empire, persistence-focused modules are designed to ensure an agent remains present even after restart, typically by hooking into mechanisms that run automatically on startup or login. Windows Run keys, logon scripts, and system boot programs are classic persistence avenues because the OS executes them without user intervention, allowing the attacker’s code to reinitialize the agent after a reboot. By placing or configuring code in these locations, the attacker can regain control without needing to reestablish a session from scratch. Other categories aren't focused on this survivability aspect. Management centers on controlling or orchestrating tools, Recon targets information gathering, and Trollsploit is not a standard category for post-exploitation workflows. So the category that best describes surviving across logoff or reboot via Run keys, logon scripts, or boot programs is persistence.

Maintaining access after a user logs off or the system reboots is what persistence is all about. In Empire, persistence-focused modules are designed to ensure an agent remains present even after restart, typically by hooking into mechanisms that run automatically on startup or login. Windows Run keys, logon scripts, and system boot programs are classic persistence avenues because the OS executes them without user intervention, allowing the attacker’s code to reinitialize the agent after a reboot. By placing or configuring code in these locations, the attacker can regain control without needing to reestablish a session from scratch.

Other categories aren't focused on this survivability aspect. Management centers on controlling or orchestrating tools, Recon targets information gathering, and Trollsploit is not a standard category for post-exploitation workflows. So the category that best describes surviving across logoff or reboot via Run keys, logon scripts, or boot programs is persistence.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy