Could legitimate administration look like command and control?¶
Yes. Management and support platforms check in, receive tasks, run scripts, transfer files and report results - the same broad pattern as command and control. Automation or encryption does not decide whether the activity is malicious.
Compare with the management baseline¶
Identify the approved tool, tenant, operator, job, target and command. Match it with tickets, deployment schedules, normal destinations, expected devices and standard templates.
Endpoint evidence may show only a trusted agent. Preserve upstream authentication, job creation, approval and command records to determine who or what instructed it.
Assess each task's authority¶
An approved platform can be hijacked, and a legitimate operator can act outside scope. An unusual one-off command from an unfamiliar source carries different weight from scheduled maintenance, but missing approval alone does not prove malice.
Do not classify the whole platform session from one task. Compare each command, target and result with its authorised purpose, and preserve deviations that connect to persistence, collection or other incident activity.
Key takeaway
Distinguish management from command and control using upstream operator, job, approval and command evidence - not the trusted agent or traffic pattern alone.