A SOC analyst reviews EDR telemetry showing a newly created scheduled task that launches a PowerShell script at system startup and runs as SYSTEM. The script was added after a user opened a malicious document. Which ATT&CK tactic does this behavior most directly represent?
Select an answer to reveal the explanation.
Short Explanation
Think of persistence like a key left in your door: it keeps the intruder coming back, even if they already have a master key. If you see a scheduled task that fires at reboot, that is classic persistence, even when it runs as SYSTEM. Don't confuse the account it runs under with the tactic of staying installed.
Full Explanation
A scheduled task that launches a script at system startup or after reboot is a classic persistence mechanism because its primary purpose is to maintain execution across restarts. In ATT&CK terms, this maps to Persistence, specifically scheduled task or job techniques. The fact that the task runs as SYSTEM does not automatically make it privilege escalation; SYSTEM may be the intended execution context, while escalation would require evidence that the actor gained higher privileges than previously held. Privilege escalation is wrong when the observable is a recurring boot-time task rather than a token abuse, vulnerable driver, UAC bypass, or other path to higher rights. Defense evasion is wrong when the behavior is not primarily hiding activity, disabling logging, masquerading as a legitimate process, or clearing artifacts. Lateral movement is wrong because no evidence shows the analyst is pivoting from one host to another using credentials, remote services, or network authentication. Exam caveat: classify the tactic by the attacker's immediate objective shown in telemetry, not by the account name or tool name. Operational check: inspect the task creation event, action path, trigger, account, and creation time, then compare it with known good scheduled tasks before tagging the alert as persistence.