CompTIA SecurityX (CAS-005)Security OperationsHard

A security analyst is reviewing a server's scheduled tasks and finds an entry configured to execute a PowerShell script every 30 minutes. The script attempts to connect to an external IP address and download a file if the connection is successful. The script uses obfuscated code and is not digitally signed. There is no legitimate business reason for this server to perform such a task. What MITRE ATT&CK technique does this most closely align with?

  1. AT1105 - Ingress Tool Transfer
  2. BT1053.005 - Scheduled Task/Job
  3. CT1071.001 - Standard Application Layer Protocol
  4. DT1059.001 - PowerShell
Show answer & explanation

Correct answer: B. T1053.005 - Scheduled Task/Job

The primary indicator is the use of a 'scheduled task' to execute malicious activity. While PowerShell (T1059.001) is used, and it performs ingress tool transfer (T1105) and uses standard application layer protocols, the *method of persistence and execution* described (a scheduled task running periodically) directly maps to T1053.005 - Scheduled Task/Job.

Why the other options are wrong

  • A. T1105 (Ingress Tool Transfer) describes the script's action of 'download a file', but it's the *scheduled execution* that's the primary technique being asked about.
  • C. T1071.001 (Standard Application Layer Protocol) describes the script's communication method ('connect to an external IP address'), but not the execution mechanism.
  • D. T1059.001 (PowerShell) is used by the script, but it describes the *means* of execution, not the *method of persistence* or execution trigger.

MITRE ATT&CK T1053.005

Scheduled Task/Job - Adversaries can abuse the Windows Task Scheduler or Linux cron jobs to execute programs, commands, or scripts on a a periodic basis to achieve persistence or perform other malicious activities.

  • Used for persistence and execution.
  • Leverages legitimate system utilities.
  • Can be configured to run at specific times or intervals.
  • Detection involves monitoring scheduled tasks and their associated scripts/commands.

Memory trick: The ghost keeps coming back at the same time every day.

More Security Operations questions