A SOC analyst compares two incidents from last week. Incident A shows an EDR alert for a new scheduled task running a PowerShell command from %APPDATA%. Incident B shows proxy logs with periodic HTTPS beaconing to a newly registered domain. Which finding provides the strongest evidence that both incidents belong to the same adversary campaign?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: TTPs are the adversary's fingerprints, not just the tools they touched. If both incidents map to the same ATT&CK technique IDs, you have repeatable tradecraft worth linking, while timestamps or hashes can drift. The trap is treating weak proximity as proof.
Full Explanation
Attack methodology frameworks such as MITRE ATT&CK are used to describe adversary behavior as tactics, techniques, and procedures, so correlation becomes strongest when two incidents share repeatable TTPs. In this case, matching technique identifiers for persistence and command-and-control shows the same operational pattern even if payloads, infrastructure, or timestamps change. That makes matched ATT&CK technique IDs the best evidence of campaign linkage. Similar target systems and close alert timestamps may indicate a common window or environment, but they do not prove the same actor or campaign because unrelated activity can occur near the same time or on similar hosts. Identical file hashes and destination addresses can support a technical connection, yet they are indicators of compromise that may be reused, changed, or absent across stages, so they are weaker than behavioral TTP matching. Comparable CVSS scores and vulnerability descriptions describe weaknesses, not adversary behavior, and cannot link two incidents to one campaign. Exam caveat: CompTIA often rewards TTP correlation over IOC similarity when asking about attack methodology frameworks. Operational check: map each alert to ATT&CK techniques, then compare technique pairs across incidents before declaring correlation.