A SOC analyst notices encoded PowerShell execution, a scheduled task creation, and SMB admin share access on a single workstation. Which action best translates this telemetry into recognized adversary behavior?
Select an answer to reveal the explanation.
Short Explanation
Think of MITRE ATT&CK like a common language for what attackers do. You map those messy logs to techniques, and suddenly the incident has shape instead of just noise. That's how you hunt behavior, not just alerts.
Full Explanation
MITRE ATT&CK serves as a shared taxonomy for adversary tactics, techniques, and procedures, so mapping telemetry to specific techniques converts raw indicators into recognizable behavioral patterns. Observed indicators can be associated with execution, persistence, and lateral movement techniques, which helps an analyst assess scope, compare incidents, and guide hunting or detection engineering. Assigning CVSS severity is inappropriate here because CVSS scores software vulnerabilities and their exploitability, not the observed actions of an attacker. Blocking the workstation at the perimeter firewall may be a containment step, but it does not explain what the attacker is doing or how the activity fits known adversary tradecraft. Creating a SIEM correlation rule is valuable for future detection, yet it is a downstream detection-engineering task rather than the immediate action that translates current telemetry into recognized adversary behavior. Exam caveat: when the stem asks for translation into recognized behavior, choose the taxonomy-based mapping action, not scoring, containment, or rule creation. Operational check: review the EDR and Windows event records, attach MITRE ATT&CK technique identifiers and tactics to each relevant event, and use that mapping to validate whether related hosts show the same behavior.