QuestionQ214
Detecting Evasive and Post-Exploitation TechniquesAn analyst suspects an attacker used the built-in MSBuild tool to compile msfvenom code. What evidence could the analyst seek to validate this theory?
- A Program execution from hidden directories
- B Altered copies of MSBuild on the filesystem
- C Encrypted TCP connections
- D Downloading of a shellcode wrapper
Community Discussion