An EDR alert shows a single workstation authenticating to ADMIN$ and IPC$ on many servers within 10 minutes, using valid credentials and no local privilege escalation. The analyst sees no unusual scheduled tasks or PowerShell command lines. Which indicator should the analyst prioritize as the likely activity type?
Select an answer to reveal the explanation.
Short Explanation
Think of admin shares like the service doors behind a building: if one badge suddenly opens many side entrances, you are not dealing with a normal user. That pattern usually points to credential-based lateral movement, not a local privilege escalation or scheduled-task persistence trap.
Full Explanation
Repeated authenticated access to Windows administrative shares from a single endpoint should be interpreted as credential-based lateral movement when no local escalation is visible. ADMIN$ exposes a server's OS directory and IPC$ supports named-pipe and remote management traffic, so valid account access to those shares from a non-admin endpoint is a classic way to move sideways, stage tools, or enable remote execution. A persistence focus would be wrong because scheduled-task abuse requires evidence of task creation, task scheduler events, or new logon sessions; remote share access alone does not establish persistence. A privilege-escalation focus is also wrong because token manipulation or local UAC bypass occurs on a host to gain higher rights, whereas the observed behavior is many remote SMB connections. A command-and-control focus is wrong because DNS tunneling appears as high-volume, unusually long, or encoded DNS queries to external resolvers, not as SMB administrative share connections. Exam caveat: the correct tactic is lateral movement even when the credentials are valid and no local escalation is visible. Operational check: pivot the SIEM to SMB file-share audit events and logon type 3 records, then list every target server reached by the workstation within the alert window.