A SOC analyst reviews EDR telemetry showing a PowerShell process spawning a new scheduled task named 'SysUpdateCheck' running from %AppData%\Roaming\Temp. The task triggers a script that downloads a payload from an IP address 10 minutes after system boot. Which indicator of compromise (IOC) best characterizes this specific behavior?
Select an answer to reveal the explanation.
Short Explanation
Think of it like an attacker leaving a key under your door mat so they can keep coming back after a reboot. That scheduled task in a temp folder is persistence, not the initial break-in.
Full Explanation
The scenario describes an attacker establishing a foothold that survives system restarts, which is the definition of persistence in the MITRE ATT&CK framework. By creating a scheduled task in a user-writable directory like AppData\Roaming\Temp, the adversary ensures their malicious script executes automatically upon system boot or at defined intervals. This technique allows the malware to re-establish command and control without requiring user interaction. Command and Control via DNS Tunneling is incorrect because the traffic described is a direct download from an IP address, not data exfiltrated or encoded within DNS queries. Initial Access via Exploit Public-Facing Application is incorrect because the scheduled task represents post-compromise activity, not the initial vector used to breach the perimeter. Credential Access via OS Credential Dumping is incorrect as there is no evidence of memory scraping or access to LSASS processes; the activity is focused on execution and scheduling, not extracting authentication secrets. Exam caveat: Always distinguish between the initial breach vector and post-breach stabilization techniques like persistence. Operational check: Review scheduled task logs and file creation events in %AppData% and %Temp% directories to identify unauthorized automation scripts.