A SOC analyst reviews three incidents over 30 days: a compromised workstation, a VPN jump host, and a backup server. EDR and SIEM logs show each host beaconing to the same external IP. Using Diamond Model infrastructure reasoning, what is the most defensible conclusion?
Select an answer to reveal the explanation.
Short Explanation
Think of a shared C2 IP like seeing the same delivery van at three crime scenes: it links the scenes, but it doesn't prove the same driver ran them all. You should treat it as a correlation clue and pivot on malware, accounts, timing, and victim roles before calling it one campaign.
Full Explanation
In the Diamond Model, infrastructure is one of four nodes—adversary, capability, infrastructure, victim—used to map relationships between incidents. A repeated C2 IP is a valid pivot because the same external endpoint was used by multiple hosts, suggesting the incidents may belong to one investigation. It is not proof of a single campaign, because infrastructure can be shared by unrelated actors through bulletproof hosting, fast flux, CDN-like abuse, or commodity malware services. Treating the shared IP as definitive campaign proof is wrong because the model treats nodes as evidence to correlate, not unique identifiers; one endpoint can connect to multiple adversaries or capabilities. Requiring identical hashes or timestamps before accepting correlation is also wrong, since campaigns often reuse infrastructure with different payloads, timings, or victim sets. Dismissing infrastructure as irrelevant because the model emphasizes capability, victim, and action is incorrect; infrastructure is explicitly central. Exam caveat: choose the answer that balances correlation strength with evidentiary limits, not the most absolute claim. Operational check: pivot the IP in SIEM and EDR for ASN, JA3, DNS, process lineage, accounts, and time windows; if incidents share infrastructure plus capability or victim context, open a campaign case.