Skip to content
CIM-155 Cyber Incidents & Offender Methods

Could legitimate administration look like command and control?

The practical answer

Yes. Legitimate administration can resemble command-and-control activity.

The key evidential caution

The dangerous assumption is that repeated remote check-ins, tasking and command execution are inherently malicious.

Management and support platforms routinely:

Key points

  • check device status
  • send commands
  • deploy software
  • collect inventory
  • transfer files
  • run scripts
  • report results

Investigators should compare the activity with:

  • approved tools
  • administrator accounts
  • management-platform records
  • support tickets
  • deployment schedules
  • normal destinations
  • expected devices
  • usual commands

Evidential limits

Do not accept legitimacy solely because the tool is approved.

The account may have been compromised, or the tool may have been used outside authorised purpose.

Likewise, do not classify ordinary management traffic as malicious merely because it is automated or encrypted.

The distinction may lie in account, target, command content, timing, source device and follow-on activity.

Preserve the upstream management records because the endpoint may show only a trusted agent performing the action.

A legitimate management channel may also be hijacked. In that case, trusted infrastructure and agents carry unauthorised commands. Preserve operator authentication, job creation, approval and command records from the management platform rather than relying only on the endpoint’s trusted-agent activity.

Compare suspicious commands with the platform’s normal deployment templates. A trusted agent performing an unusual one-off command outside an approved job may be more significant than routine automated maintenance.

Where approval records are missing, preserve that fact without assuming the activity was unauthorised or malicious in the specific circumstances.

Operational takeaway

Test suspected command-and-control activity against the organisation’s real remote-management baseline and assess each task for authority, source and purpose.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.