During an incident response, an analyst extracts a file from a PCAP using Wireshark's 'Export Objects' feature. The file contains shellcode that uses NOP sleds and encodes a reverse shell command. Which Cyber Kill Chain phase does this file represent?
Trap 1: Installation
Installation occurs after exploitation; the file may not yet be installed.
Trap 2: Actions on Objectives
This is later in the kill chain; the file is being delivered.
Trap 3: Weaponization
Weaponization is the creation of the payload, not the file as seen in transit.
- A
Installation
Why it fails: Installation occurs after exploitation; the file may not yet be installed.
- B
Actions on Objectives
Why it fails: This is later in the kill chain; the file is being delivered.
- C
Delivery
The file was delivered over the network, so it is in the delivery phase.
- D
Weaponization
Why it fails: Weaponization is the creation of the payload, not the file as seen in transit.