QuestionQ18

Threat Hunting Techniques

Refer to the exhibit.

Question Image

After receiving an alert that a Windows host authenticated over the network to another host using a local administrator account, the security team examines the host. The team finds a process-creation event in that host's Sysmon logs.

Which action did the host carry out?

Explanation

The command uses WMIC with /node:192.168.189.155 and credentials to create a process on another Windows host through WMI. Executing a command remotely on a second host after network authentication is lateral movement. Sysmon Event ID 1 records the full command line and process details needed to identify this remote execution.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!