A phishing email delivers a malicious attachment to a finance user. The user opens the attachment, and a PowerShell script immediately runs and connects outbound to a C2 server. Which ATT&CK tactic describes the first successful adversary action?
Select an answer to reveal the explanation.
Short Explanation
Think of it like a break-in: handing the burglar a key is the foothold, and opening the door with it is what happens next. The malicious attachment is your first successful Initial Access event, not the PowerShell run. Don't let the flashy execution step pull you away from the tactic that actually got the adversary in.
Full Explanation
In the MITRE ATT&CK framework, tactics describe adversary goals at a stage of the intrusion, while techniques describe how those goals are achieved. A malicious attachment delivered by phishing is an Initial Access technique because its purpose is to obtain a foothold inside the target environment. The user opening the attachment is the event that makes that foothold successful, so the first successful adversary action maps to Initial Access. Execution is a separate tactic that covers the subsequent running of the delivered code, such as PowerShell launching from the attachment, and is important but not the first foothold. Command and Control covers the adversary's attempts to communicate with compromised systems, so the outbound C2 connection occurs after the foothold and execution have already happened. Lateral Movement describes movement from one compromised system to another within the environment, which is not represented by a user opening a phishing attachment on the first endpoint. Exam caveat: ATT&CK questions often include several tactics in one incident; identify the first action that satisfies the adversary's stated goal, not the later consequence. Operational check: map each alert in a phishing chain to its tactic before escalating, starting with delivery and user interaction as Initial Access and only assigning Execution after code actually runs.