Question: If an attacker uses phishing to obtain user credentials for an employee without administrator access and needs to install a rootkit backdoor that requires system
If an attacker uses phishing to obtain user credentials for an employee without administrator access and needs to install a rootkit backdoor that requires system level access, what might be the attacker's next course of action to gain the administrator privileges?
Set a scheduled task to install the rootkit the following day under the current user account.
Attempt to extract local administrator credentials stored on the machine in running memory or the registry.
Try to brute force that users password for an RDP connection to the users workstation.
Change the IP address of the users computer from DHCPassigned to static.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
