An EDR alert reports a workstation beaconing outbound. Web proxy logs are available. Which proxy log pattern most strongly indicates command-and-control traffic rather than benign activity?
Select an answer to reveal the explanation.
Short Explanation
Think of proxy logs like a toll booth: they don't show every conversation, but they reveal who went where, how often, and what car they were driving. If you see periodic GETs to a brand-new domain with a custom user agent, that looks like beaconing, not casual browsing. Don't chase big transfers or expected updates when the pattern itself screams scheduled check-in.
Full Explanation
Web proxy telemetry is useful for C2 investigation because it records the outbound request context: destination, request method, user agent, volume, timing, and category. Periodic GETs to a newly registered domain with a custom user agent align with beaconing: regular intervals, low request size, uncommon client identity, and infrastructure likely not used by normal business applications. That combination is more suspicious than a single log field alone. Large uploads to approved cloud storage during backup windows can be expected administrative or backup traffic, especially when destination category and user agent are normal. Normal browsing to categorized news sites with a standard browser user agent reflects ordinary web use and lacks beacon-like periodicity or unusual client identity. A DNS lookup for a vendor patch server followed by an update download represents expected software maintenance when the destination, timing, and transfer pattern match the vendor's update cadence. Exam caveat: choose the proxy pattern that shows regularity plus an anomalous destination or client identity, not merely high volume or an unfamiliar domain. Operational check: pivot the proxy event to DNS and EDR process telemetry, then confirm the requesting process and the destination's registration age before blocking.