
Rule Info
Name
Scheduled Task Creation with System Binary Masquerading - Security
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects scheduled task creation that may indicate masquerading attempts where attackers use eecutables to be executed same to legitimate Windows system binaries.
This technique is frequently used by adversaries to establish persistence mechanisms, bypass security controls, and hide malicious activities by blending with normal system operations.
Reference
Internal Research
Date
2025-04-07 00:00:00
Modified
None
Id
172186cd-1554-4ea6-bd9e-3c5af103929e
Tags
attack.persistence attack.t1053.005 attack.defense-evasion attack.t1036.005
Type
Nextron Sigma feed only (private)