During an investigation, analysts observe that attackers consistently avoid PowerShell logging, disable AMSI, and prefer WMI for execution. Why is this information critical for attribution?
The correct answer is it reflects the attacker's operational preferences. Attribution relies on understanding how attackers operate, not just what tools they use.
Operational preferences---such as avoiding PowerShell logging, disabling AMSI, and favoring WMI---are behavioral signatures. These patterns often persist across campaigns and are documented in threat intelligence reports associated with specific adversaries.
Option A is incorrect because malware families change frequently. Option B is unreliable due to infrastructure rotation. Option D is unrelated to post-access tradecraft.
Professional attribution focuses on:
Execution methods
Defensive evasion choices
Tooling preferences
Workflow consistency
Mapping these behaviors to MITRE ATT&CK techniques enables analysts to compare findings against known threat actor profiles. This provides higher confidence attribution than artifact-based indicators.
Thus, option C is the correct answer.
Adell
2 days agoCortney
7 days agoMa
12 days agoArthur
17 days agoViva
23 days agoAdolph
28 days agoSophia
1 month agoWhitley
1 month agoMarylou
1 month agoDevora
2 months agoTrina
2 months ago