A SOC alert shows powershell.exe -enc running a download cradle that retrieves and runs a remote file. The same process then sends small HTTP requests to that URL every 30 seconds. Which ATT&CK tactic pair best describes the initial retrieval and the periodic callbacks?
Select an answer to reveal the explanation.
Short Explanation
Think of a download cradle like a courier: its job is to get code running, not to hide in a closet. If that same code phones home on a timer, that's the command-and-control channel talking. You map the first step to execution and the callback to command-and-control.
Full Explanation
ATT&CK tactics answer what the adversary is trying to accomplish, not just the tool used. A PowerShell download cradle is primarily a way to run code on the victim, so the initial retrieval maps to execution. When the same process later makes repeated outbound requests to a fixed URL, that pattern is a beacon used to receive instructions or stage data, which maps to command-and-control. Defense evasion can appear in the same event through encoded commands or anti-analysis strings, but those are techniques supporting another tactic; they do not define the overall behavior if the visible goal is running code and calling back. Lateral movement would require the adversary to use valid credentials, remote services, or pass-the-hash to execute on another system, not merely beacon to a web endpoint. Privilege escalation would require evidence of token theft, UAC bypass, or running as SYSTEM, which the alert does not show. Exfiltration would require sensitive data leaving the network, usually in larger or targeted transfers, rather than small periodic HTTP requests. Exam caveat: when a scenario gives both a launch mechanism and a beacon, classify the first behavior by its purpose and the second by its communication pattern. Operational check: pivot from the PowerShell process tree to the URL, then review proxy or NetFlow records for beaconing cadence and any follow-on data transfer.