QuestionQ268

Detecting Exploitation and Covert Communications Tools

Which RITA threat-hunting capability is used to identify C2 activity specific to Meterpreter?

  • A Identify long lived TCP connections
  • B Review visited DNS subdomains
  • C Analyze gratuitous ARP packets
  • D Alert on IOC matching behavior
Explanation

Meterpreter reverse-TCP C2 maintains a persistent TCP session throughout the infection. RITA detects this behavioral pattern through long-connection detection, which identifies TCP connections that remain active for unusually long periods.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!