Suspicious Scheduled Task Creation

Rule Info

Name
Suspicious Scheduled Task Creation
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects suspicious scheduled task creation events. Based on attributes such as paths, commands line flags, etc.
Date
2022-12-05 00:00:00
Modified
2022-12-07 00:00:00
Id
3a734d25-df5c-4b99-8034-af1ddb5883a4
Tags
attack.execution attack.privilege-escalation attack.persistence attack.t1053.005
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Ryan Plas
Merge PR #4893 from @ryanplasma - Update Microsoft references URLS
2024-07-02
frack113
Merge PR #4479 From @frack113 - Upgrade Rules Status
2023-10-17
Nasreddine Bencherchali
chore: add nextron authors tag
2023-02-01
Nasreddine Bencherchali
fix: fix unused selection
2022-12-08
Nasreddine Bencherchali
feat: new rules and fixes (#3759)
2022-12-06
Nasreddine Bencherchali
fix: apply suggestions from code review
2022-12-06
Nasreddine Bencherchali
feat: add rules related to scheduled tasks
2022-12-05