Configuration Drift
Definition
Deviation from an approved baseline configuration, whether caused by legitimate administrative action or by an attacker modifying settings to weaken defences or enable persistence. Eradication must identify and reverse all attacker-induced configuration drift.
- Field
- Incident response, threat eradication
- Definition scope
- Deviation from an approved baseline
- Two causes
- Legitimate admin change or attacker tampering
- Eradication requirement
- Reverse all attacker-induced drift
Common questions
Why is it hard to tell benign configuration drift from attacker tampering?+
Both produce the same symptom: a live setting that no longer matches the approved baseline. Responders normally need a change log or version-controlled configuration record to determine who made a change and when, since the drift itself carries no attribution.
What happens if attacker-induced drift is missed during eradication?+
A weakened setting, disabled logging rule, or added persistence mechanism left in place gives the attacker a way back in even after malware and accounts are removed. This is why eradication playbooks require a full configuration comparison against baseline, not just malware cleanup.
Related terms
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Persistence Mechanism
- The technique malware uses to survive a reboot or user logout. Common methods include registry run keys, scheduled tasks, Windows services, cron...
- Reimaging
- Wiping a compromised system and restoring it from a known-good operating system image. Reimaging is the most reliable eradication method for host-level...
- Rogue Account
- A user or service account created by the attacker during the intrusion to maintain access independent of any compromised legitimate account. Rogue...
- Web Shell
- A script (typically PHP, ASP, or JSP) placed on a web server by an attacker to provide remote command execution via HTTP...