Rule Info
Name
Suspicious Scheduled Task Creation
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects suspicious scheduled task creation events. Based on attributes such as paths, commands line flags, etc.
Date
2022-12-05 00:00:00
Modified
2022-12-07 00:00:00
Id
3a734d25-df5c-4b99-8034-af1ddb5883a4
Tags
attack.execution attack.privilege-escalation attack.persistence attack.t1053.005
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
